VDB
KO
MEDIUM 5.0

GHSA-5fhx-9jwj-867m

Weblate: Authenticated SSRF via redirect bypass of ALLOWED_ASSET_DOMAINS in screenshot URL uploads

Details

### Impact The ALLOWED_ASSET_DOMAINS setting applied only to the first issued requests and didn't restrict possible redirects.

### Patches * https://github.com/WeblateOrg/weblate/pull/18550

### References This issue was reported by @spbavarva via GitHub.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI / weblate
Introduced in: 0 Fixed in: 5.17
Fix pip install --upgrade 'weblate>=5.17'

References