VDB
KO
MEDIUM 4.3

GHSA-gcg5-86jr-f7jg

Weblate Vulnerable to Private Translation Enumeration via Screenshot API

Details

### Impact

The screenshots, tasks, and component link API allowed for the enumeration of translations in a project inaccessible to the user.

### Patches * https://github.com/WeblateOrg/weblate/pull/19258

### Acknowledgement Weblate thanks Luay for reporting this vulnerability according to the organization's [security issues guideline](https://docs.weblate.org/en/latest/security/issues.html).

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI / weblate
Introduced in: 0 Fixed in: 5.17.1
Fix pip install --upgrade 'weblate>=5.17.1'

References