CVE-2025-68398
🟠 Łataj w tym tygodniu
Zdalne nadpisanie konfiguracji Gita w Weblate umożliwia zmianę jego zachowania.
CVSS
9.1
EPSS
0.8%
Exploit
none
Vendor
weblate
Opis źródłowy (NVD)
Weblate is a web based localization tool. In versions prior to 5.15.1, it was possible to overwrite Git configuration remotely and override some of its behavior. Version 5.15.1 fixes the issue.
brak
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 9.1 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 0.8% |
| Opublikowano (NVD) | 2025-12-18 23:15:49 UTC |
| Ostatnia modyfikacja (NVD) | 2026-09-30 23:10:00 UTC |
Referencje
- https://github.com/WeblateOrg/weblate/commit/4837a4154390f7c1d03c0e398aa6439dcfa361b4 ([email protected])
- https://github.com/WeblateOrg/weblate/commit/dd8c9d7b00eebe28770fa0e2cd96126791765ea7 ([email protected])
- https://github.com/WeblateOrg/weblate/pull/17330 ([email protected]) [Issue Tracking]
- https://github.com/WeblateOrg/weblate/pull/17345 ([email protected]) [Issue Tracking]
- https://github.com/WeblateOrg/weblate/releases/tag/weblate-5.15.1 ([email protected]) [Release Notes]
- https://github.com/WeblateOrg/weblate/security/advisories/GHSA-8vcg-cfxj-p5m3 ([email protected]) [Vendor Advisory]