CVE-2022-23915
Estado: ModificadaAlta (8.8)—
The package weblate from 0 and before 4.11.1 are vulnerable to Remote Code Execution (RCE) via argument injection when using git or mercurial repositories. Authenticated users, can change the behavior of the application in an unintended way, leading to command execution.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Puntuación base: 8.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 3.87%
- Percentil entre todas las CVEs puntuadas: 90
- Fecha de la puntuación: 7/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-88
Referencias
- https://github.com/WeblateOrg/weblate/pull/7337
- https://github.com/WeblateOrg/weblate/pull/7338
- https://github.com/WeblateOrg/weblate/releases/tag/weblate-4.11.1
- https://snyk.io/vuln/SNYK-PYTHON-WEBLATE-2414088
- https://github.com/WeblateOrg/weblate/pull/7337
- https://github.com/WeblateOrg/weblate/pull/7338
- https://github.com/WeblateOrg/weblate/releases/tag/weblate-4.11.1
- https://snyk.io/vuln/SNYK-PYTHON-WEBLATE-2414088
JSON original (NVD)
Mostrar
{
"id": "CVE-2022-23915",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 6.5,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:S/C:P/I:P/A:P",
"authentication": "SINGLE",
"integrityImpact": "PARTIAL",
"accessComplexity": "LOW",
"availabilityImpact": "PARTIAL",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 6.4,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 8,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "report@snyk.io",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 7.2,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "HIGH",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 1.2
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 8.8,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "LOW",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 2.8
}
]
},
"affected": [
{
"source": "report@snyk.io",
"affectedData": [
{
"vendor": "n/a",
"product": "Weblate",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "unspecified",
"versionType": "custom"
},
{
"status": "affected",
"version": "unspecified",
"lessThan": "4.11.1",
"versionType": "custom"
}
]
}
]
}
],
"published": "2022-03-04T20:15:07.757",
"references": [
{
"url": "https://github.com/WeblateOrg/weblate/pull/7337",
"tags": [
"Patch",
"Third Party Advisory"
],
"source": "report@snyk.io"
},
{
"url": "https://github.com/WeblateOrg/weblate/pull/7338",
"tags": [
"Patch",
"Third Party Advisory"
],
"source": "report@snyk.io"
},
{
"url": "https://github.com/WeblateOrg/weblate/releases/tag/weblate-4.11.1",
"tags": [
"Patch",
"Release Notes",
"Third Party Advisory"
],
"source": "report@snyk.io"
},
{
"url": "https://snyk.io/vuln/SNYK-PYTHON-WEBLATE-2414088",
"tags": [
"Patch",
"Third Party Advisory"
],
"source": "report@snyk.io"
},
{
"url": "https://github.com/WeblateOrg/weblate/pull/7337",
"tags": [
"Patch",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://github.com/WeblateOrg/weblate/pull/7338",
"tags": [
"Patch",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://github.com/WeblateOrg/weblate/releases/tag/weblate-4.11.1",
"tags": [
"Patch",
"Release Notes",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://snyk.io/vuln/SNYK-PYTHON-WEBLATE-2414088",
"tags": [
"Patch",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-88"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "The package weblate from 0 and before 4.11.1 are vulnerable to Remote Code Execution (RCE) via argument injection when using git or mercurial repositories. Authenticated users, can change the behavior of the application in an unintended way, leading to command execution."
},
{
"lang": "es",
"value": "El paquete weblate desde la versión 0 y anteriores a 4.11.1 son vulnerables a una Ejecución de Código Remota (RCE) por medio de una inyección de argumentos cuando son usados repositorios git o mercurial. Los usuarios autenticados, pueden cambiar el comportamiento de la aplicación de una manera no intencionada, conllevando a una ejecución de comandos"
}
],
"lastModified": "2026-06-17T04:30:57.837",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:weblate:weblate:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C5AA9094-8C38-49F3-B1E3-AA59A60363AF",
"versionEndExcluding": "4.11.1"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "report@snyk.io"
}