PT-2025-25575 · Weblate · Weblate
Micael1
·
Published
2025-06-16
·
Updated
2025-07-16
·
CVE-2025-49134
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Weblate versions prior to 5.12
Description
The issue concerns the inclusion of the full IP address of the acting user in audit log notifications. This information could be obtained by third-party servers, such as SMTP relays or spam filters.
Recommendations
For versions prior to 5.12, update to version 5.12 to resolve the issue. As a temporary workaround, consider restricting access to audit log notifications to minimize the risk of IP address exposure.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Weblate