CVE-2022-23915
published 2022-03-04CVE-2022-23915: The package weblate from 0 and before 4.11.1 are vulnerable to Remote Code Execution (RCE) via argument injection when using git or mercurial repositories…
PriorityP358high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
3.87%
89.8th percentile
The package weblate from 0 and before 4.11.1 are vulnerable to Remote Code Execution (RCE) via argument injection when using git or mercurial repositories. Authenticated users, can change the behavior of the application in an unintended way, leading to command execution.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| weblate | weblate | < unspecified | unspecified |
| weblate | weblate | < 4.11.1 | 4.11.1 |
| weblate | weblate | < d83672a3e7415da1490334e2c9431e5da1966842 | d83672a3e7415da1490334e2c9431e5da1966842 |
| weblate | weblate | >= 0 < 4.11.1 | 4.11.1 |
| weblate | weblate | >= 0 < 35d59f1f040541c358cece0a8d4a63183ca919b8 | 35d59f1f040541c358cece0a8d4a63183ca919b8 |
| weblate | weblate | >= unspecified < 4.11.1 | 4.11.1 |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Duplicate Advisory: Command injection in Weblate
osv·2022-03-05
CVE-2022-23915 [HIGH] Duplicate Advisory: Command injection in Weblate
Duplicate Advisory: Command injection in Weblate
## Duplicate Advisory
This advisory has been withdrawn because it is a duplicate of GHSA-3872-f48p-pxqj. This link is maintained to preserve external references.
## Original Description
Weblate is a web based localization tool with tight version control integration. Prior to version 4.11.1, Weblate didn't properly sanitize some arguments passed to Git and Mercurial, allowing them to change their behavior in an unintended way. Instances where untrusted users cannot create new components are not affected. The issues were fixed in the 4.11.1 release.
OSV
Improper Neutralization of Special Elements used in a Command ('Command Injection') in Weblate
osv·2022-03-04
CVE-2022-23915 [HIGH] Improper Neutralization of Special Elements used in a Command ('Command Injection') in Weblate
Improper Neutralization of Special Elements used in a Command ('Command Injection') in Weblate
### Impact
Weblate didn't correctly sanitize some arguments passed to Git and Mercurial, which allowed changing their behavior in an unintended way.
### Patches
The issues were fixed in the 4.11.1 release. The following commits are addressing it:
* 35d59f1f040541c358cece0a8d4a63183ca919b8
* d83672a3e7415da1490334e2c9431e5da1966842
### Workarounds
Instances in which untrusted users cannot create new components are not affected.
### References
* [SNYK-PYTHON-WEBLATE-2414088](https://security.snyk.io/vuln/SNYK-PYTHON-WEBLATE-2414088)
### For more information
If you have any questions or comments about this advisory:
* Open a topic in [discussions](https://github.com/WeblateOrg/weblate/discus
OSV
CVE-2022-23915: The package weblate from 0 and before 4
osv·2022-03-04
CVE-2022-23915 CVE-2022-23915: The package weblate from 0 and before 4
The package weblate from 0 and before 4.11.1 are vulnerable to Remote Code Execution (RCE) via argument injection when using git or mercurial repositories. Authenticated users, can change the behavior of the application in an unintended way, leading to command execution.
GHSA
Improper Neutralization of Special Elements used in a Command ('Command Injection') in Weblate
ghsa·2022-03-04
CVE-2022-23915 [HIGH] CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection') in Weblate
Improper Neutralization of Special Elements used in a Command ('Command Injection') in Weblate
### Impact
Weblate didn't correctly sanitize some arguments passed to Git and Mercurial, which allowed changing their behavior in an unintended way.
### Patches
The issues were fixed in the 4.11.1 release. The following commits are addressing it:
* 35d59f1f040541c358cece0a8d4a63183ca919b8
* d83672a3e7415da1490334e2c9431e5da1966842
### Workarounds
Instances in which untrusted users cannot create new components are not affected.
### References
* [SNYK-PYTHON-WEBLATE-2414088](https://security.snyk.io/vuln/SNYK-PYTHON-WEBLATE-2414088)
### For more information
If you have any questions or comments about this advisory:
* Open a topic in [discussions](https://github.com/WeblateOrg/weblate/discus
OSV
CVE-2022-23915: Weblate is a web based localization tool with tight version control integration
osv·2022-03-04
CVE-2022-23915 CVE-2022-23915: Weblate is a web based localization tool with tight version control integration
Weblate is a web based localization tool with tight version control integration. Prior to version 4.11.1, Weblate didn't properly sanitize some arguments passed to Git and Mercurial, allowing them to change their behavior in an unintended way. Instances where untrusted users cannot create new components are not affected. The issues were fixed in the 4.11.1 release.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/WeblateOrg/weblate/pull/7337https://github.com/WeblateOrg/weblate/pull/7338https://github.com/WeblateOrg/weblate/releases/tag/weblate-4.11.1https://snyk.io/vuln/SNYK-PYTHON-WEBLATE-2414088https://github.com/WeblateOrg/weblate/pull/7337https://github.com/WeblateOrg/weblate/pull/7338https://github.com/WeblateOrg/weblate/releases/tag/weblate-4.11.1https://snyk.io/vuln/SNYK-PYTHON-WEBLATE-2414088
2022-03-04
Published