The package weblate from 0 and before 4.11.1 are vulnerable to Remote Code Execution (RCE) via argument injection when using git or mercurial repositories. Authenticated users, can change the behavior of the application in an unintended way, leading to command execution.
References
Link Resource
https://github.com/WeblateOrg/weblate/pull/7337 Patch Third Party Advisory
https://github.com/WeblateOrg/weblate/pull/7338 Patch Third Party Advisory
https://github.com/WeblateOrg/weblate/releases/tag/weblate-4.11.1 Patch Release Notes Third Party Advisory
https://snyk.io/vuln/SNYK-PYTHON-WEBLATE-2414088 Patch Third Party Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: snyk

Published: 2022-03-04T00:00:00

Updated: 2022-03-04T20:00:13

Reserved: 2022-02-24T00:00:00


Link: CVE-2022-23915

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2022-03-04T20:15:07.757

Modified: 2022-03-12T01:58:54.757


Link: CVE-2022-23915

JSON object: View

cve-icon Redhat Information

No data.

CWE