CVE-2024-39303

Source
https://cve.org/CVERecord?id=CVE-2024-39303
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-39303.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2024-39303
Aliases
Downstream
Related
Published
2024-07-01T18:46:18.183Z
Modified
2025-12-05T05:18:43.201594Z
Severity
  • 4.4 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:N CVSS Calculator
Summary
Weblate vulnerabler to improper sanitization of project backups
Details

Weblate is a web based localization tool. Prior to version 5.6.2, Weblate didn't correctly validate filenames when restoring project backup. It may be possible to gain unauthorized access to files on the server using a crafted ZIP file. This issue has been addressed in Weblate 5.6.2. As a workaround, do not allow untrusted users to create projects.

Database specific
{
    "cwe_ids": [
        "CWE-73"
    ],
    "cna_assigner": "GitHub_M",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/39xxx/CVE-2024-39303.json"
}
References

Affected packages

Git / github.com/weblateorg/weblate

Affected ranges

Type
GIT
Repo
https://github.com/weblateorg/weblate
Events

Affected versions

weblate-4.*

weblate-4.14
weblate-4.14.1
weblate-4.14.2
weblate-4.15
weblate-4.15.1
weblate-4.15.2
weblate-4.16
weblate-4.16.1
weblate-4.16.2
weblate-4.16.3
weblate-4.16.4
weblate-4.17
weblate-4.18
weblate-4.18.1
weblate-4.18.2

weblate-5.*

weblate-5.0
weblate-5.0.1
weblate-5.0.2
weblate-5.1
weblate-5.1.1
weblate-5.2
weblate-5.2.1
weblate-5.3
weblate-5.3.1
weblate-5.4
weblate-5.4.1
weblate-5.4.2
weblate-5.4.3
weblate-5.5
weblate-5.5.1
weblate-5.5.2
weblate-5.5.3
weblate-5.5.4
weblate-5.5.5
weblate-5.6
weblate-5.6.1

Database specific

source

"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-39303.json"