CVE-2025-64326
Weblate leaks the IP of project member inviting user to be reviewer in Audit log
2.6
LOW
CVSS 3.1
EPSS 0.18%
描述
Weblate is a web based localization tool. In versions 5.14 and below, Weblate leaks the IP address of the project member inviting the user to the project in the audit log. The audit log includes IP addresses from admin-triggered actions, which can be viewed by invited users. This issue is fixed in version 5.14.1.
如何修補 CVE-2025-64326
要修補 CVE-2025-64326,請將受影響套件升級到下列已修補版本。
- —升級至 5.14.1 或更新版本
- —升級至 5.14.1 或更新版本
- —升級至 5.14.1 或更新版本
CVE-2025-64326 正在被利用嗎?
低 — EPSS 為 0.2%,目前沒有觀察到大規模利用活動。
受影響套件(3)
- from 0, < 5.14.1
- from 0, < 5.14.1
- from 0, < 5.14.1
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | LOW2.6 | CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:N/A:N |