VDB
KO
LOW

GHSA-3g2f-4rjg-9385

Weblate leaks information via screenshots

Details

### Impact The screenshot images were served directly by the HTTP server without proper access control. This could allow an unauthenticated user to access screenshots after guessing their filename.

### Patches * https://github.com/WeblateOrg/weblate/pull/17516

### References

Thanks to Lukas May and Michael Leu for reporting this.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI / weblate
Introduced in: 0 Fixed in: 5.15.2
Fix pip install --upgrade 'weblate>=5.15.2'

References