CVE-2025-58352
⚪ Do wiadomości
Obejście limitu czasu sesji w Weblate umożliwia atak na weryfikację drugiego czynnika.
CVSS
6.5
EPSS
0.3%
Exploit
none
Vendor
weblate
Opis źródłowy (NVD)
Weblate is a web based localization tool. Versions lower than 5.13.1 contain a vulnerability that causes long session expiry during the second factor verification. The long session expiry could be used to circumvent rate limiting of the second factor. This issue is fixed in version 5.13.1.
brak
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 6.5 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 0.3% |
| Opublikowano (NVD) | 2025-09-05 00:15:32 UTC |
| Ostatnia modyfikacja (NVD) | 2026-09-30 23:10:00 UTC |
Referencje
- https://github.com/WeblateOrg/weblate/commit/0b46fe596231dd456283ead66699ae5516f23908 ([email protected]) [Patch]
- https://github.com/WeblateOrg/weblate/pull/16002 ([email protected]) [Issue Tracking]
- https://github.com/WeblateOrg/weblate/security/advisories/GHSA-377j-wj38-4728 ([email protected]) [Vendor Advisory]