CVE-2022-23915
Last modified
CVE-2022-23915 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. The package weblate from 0 and before 4.11.1 are vulnerable to Remote Code Execution (RCE) via argument injection when using git or mercurial repositories. Authenticated users, can change the behavior of the application in an unintended way, leading to command execution.. EPSS estimates a 2.86% chance of exploitation in the next 30 days.
Description
The package weblate from 0 and before 4.11.1 are vulnerable to Remote Code Execution (RCE) via argument injection when using git or mercurial repositories. Authenticated users, can change the behavior of the application in an unintended way, leading to command execution.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Weblate | Weblate | < 4.11.1 |
References
- https://github.com/WeblateOrg/weblate/pull/7337Patch, Third Party Advisory
- https://github.com/WeblateOrg/weblate/pull/7338Patch, Third Party Advisory
- https://github.com/WeblateOrg/weblate/releases/tag/weblate-4.11.1Patch, Release Notes, Third Party Advisory
- https://snyk.io/vuln/SNYK-PYTHON-WEBLATE-2414088Patch, Third Party Advisory
- https://github.com/WeblateOrg/weblate/pull/7337Patch, Third Party Advisory
- https://github.com/WeblateOrg/weblate/pull/7338Patch, Third Party Advisory
- https://github.com/WeblateOrg/weblate/releases/tag/weblate-4.11.1Patch, Release Notes, Third Party Advisory
- https://snyk.io/vuln/SNYK-PYTHON-WEBLATE-2414088Patch, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-23915?
How severe is CVE-2022-23915?
How do I fix CVE-2022-23915?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2022
- CVE-2022-23909There is an unquoted service path in Sherpa Connector Servic…7.8
- CVE-2022-2391The Inspiro PRO WordPress plugin does not sanitize the portf…5.4
- CVE-2022-23911The Testimonial WordPress Plugin WordPress plugin before 1.4…7.2
- CVE-2022-23912The Testimonial WordPress Plugin WordPress plugin before 1.4…6.1
- CVE-2022-23913In Apache ActiveMQ Artemis prior to 2.20.0 or 2.19.1, an att…7.5
- CVE-2022-23914Rejected reason: This CVE ID has been rejected or withdrawn …
- CVE-2022-23916Cross-site scripting vulnerability in a-blog cms Ver.2.8.x s…6.1
- CVE-2022-23917Rejected reason: This CVE ID has been rejected or withdrawn …
- CVE-2022-23918A stack-based buffer overflow vulnerability exists in the co…9.8
- CVE-2022-23919A stack-based buffer overflow vulnerability exists in the co…9.8
- CVE-2022-2392The Lana Downloads Manager WordPress plugin before 1.8.0 is …6.5
- CVE-2022-23921Exploitation of this vulnerability may result in local privi…7.8
Are you affected by CVE-2022-23915?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
