CVE-2025-49134

Weblate is a web based localization tool. Prior to version 5.12, the audit log notifications included the full IP address of the acting user. This could be obtained by third-party servers such as SMTP relays, or spam filters. This issue has been patched in version 5.12.
CVSS

No CVSS.

Configurations

No configuration.

History

17 Jun 2025, 20:50

Type Values Removed Values Added
Summary
  • (es) Weblate es una herramienta de localización web. Antes de la versión 5.12, las notificaciones del registro de auditoría incluían la dirección IP completa del usuario. Esta podía obtenerse mediante servidores externos, como repetidores SMTP o filtros de spam. Este problema se ha corregido en la versión 5.12.

16 Jun 2025, 21:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-06-16 21:15

Updated : 2025-06-17 20:50


NVD link : CVE-2025-49134

Mitre link : CVE-2025-49134

CVE.ORG link : CVE-2025-49134


JSON object : View

Products Affected

No product.

CWE
CWE-359

Exposure of Private Personal Information to an Unauthorized Actor