[Bug 1227273] New: VUL-0: CVE-2024-39303: Weblate is a web based localization tool. Prior to version 5.6.2, Weblate didn't correctly validate filenames when restoring project backup. It may be possible to gain unauthorized access to files on the server using a crafted ...
https://bugzilla.suse.com/show_bug.cgi?id=1227273 Bug ID: 1227273 Summary: VUL-0: CVE-2024-39303: Weblate is a web based localization tool. Prior to version 5.6.2, Weblate didn't correctly validate filenames when restoring project backup. It may be possible to gain unauthorized access to files on the server using a crafted ... Classification: openSUSE Product: openSUSE Distribution Version: Leap 15.6 Hardware: Other URL: https://smash.suse.de/issue/412574/ OS: Other Status: NEW Severity: Normal Priority: P5 - None Component: Security Assignee: mcepl@suse.com Reporter: smash_bz@suse.de QA Contact: security-team@suse.de CC: stoyan.manolov@suse.com Target Milestone: --- Found By: Security Response Team Blocker: --- Weblate is a web based localization tool. Prior to version 5.6.2, Weblate didn't correctly validate filenames when restoring project backup. It may be possible to gain unauthorized access to files on the server using a crafted ZIP file. This issue has been addressed in Weblate 5.6.2. As a workaround, do not allow untrusted users to create projects. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2024-39303 https://www.cve.org/CVERecord?id=CVE-2024-39303 https://github.com/WeblateOrg/weblate/commit/b6a7eace155fa0feaf01b4ac36165a9... https://github.com/WeblateOrg/weblate/security/advisories/GHSA-jfgp-674x-6q4... -- You are receiving this mail because: You are on the CC list for the bug.
https://bugzilla.suse.com/show_bug.cgi?id=1227273 SMASH SMASH <smash_bz@suse.de> changed: What |Removed |Added ---------------------------------------------------------------------------- Priority|P5 - None |P3 - Medium -- You are receiving this mail because: You are on the CC list for the bug.
https://bugzilla.suse.com/show_bug.cgi?id=1227273 Matej Cepl <mcepl@suse.com> changed: What |Removed |Added ---------------------------------------------------------------------------- Assignee|mcepl@suse.com |nico.krapp@suse.com -- You are receiving this mail because: You are on the CC list for the bug.
https://bugzilla.suse.com/show_bug.cgi?id=1227273 https://bugzilla.suse.com/show_bug.cgi?id=1227273#c1 Markéta Machová <mmachova@suse.com> changed: What |Removed |Added ---------------------------------------------------------------------------- CC| |mmachova@suse.com Product|openSUSE Distribution |openSUSE Tumbleweed Version|Leap 15.6 |Current Component|Security |Security --- Comment #1 from Markéta Machová <mmachova@suse.com> --- Hi all, there is no weblate in Leap 15.6. Yes, it used to be built for Leap, but it wasn't in the supported stack, it was only for an in-house use. I think the "Product" field should be corrected to "openSUSE Tumbleweed", if it is possible. -- You are receiving this mail because: You are on the CC list for the bug.
https://bugzilla.suse.com/show_bug.cgi?id=1227273 https://bugzilla.suse.com/show_bug.cgi?id=1227273#c2 Markéta Machová <mmachova@suse.com> changed: What |Removed |Added ---------------------------------------------------------------------------- Status|NEW |IN_PROGRESS Assignee|nico.krapp@suse.com |mmachova@suse.com --- Comment #2 from Markéta Machová <mmachova@suse.com> --- Update in progress in my home project. -- You are receiving this mail because: You are on the CC list for the bug.
https://bugzilla.suse.com/show_bug.cgi?id=1227273 https://bugzilla.suse.com/show_bug.cgi?id=1227273#c3 --- Comment #3 from Markéta Machová <mmachova@suse.com> --- sent to Factory: https://build.opensuse.org/request/show/1188419 -- You are receiving this mail because: You are on the CC list for the bug.
https://bugzilla.suse.com/show_bug.cgi?id=1227273 https://bugzilla.suse.com/show_bug.cgi?id=1227273#c4 Markéta Machová <mmachova@suse.com> changed: What |Removed |Added ---------------------------------------------------------------------------- Assignee|mmachova@suse.com |security-team@suse.de --- Comment #4 from Markéta Machová <mmachova@suse.com> --- fixed in Factory a long time ago -- You are receiving this mail because: You are on the CC list for the bug.
participants (1)
-
bugzilla_noreply@suse.com