PT-2026-2970 · Pypi · Weblate

Publicado

2026-01-14

·

Atualizado

2026-01-14

CVSS v4.0

2.3

Baixa

VetorAV:N/AC:H/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N

Impact

The screenshot images were served directly by the HTTP server without proper access control. This could allow an unauthenticated user to access screenshots after guessing their filename.

Patches

References

Thanks to Lukas May and Michael Leu for reporting this.

Correção

Improper Access Control

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

GHSA-3G2F-4RJG-9385

Produtos afetados

Weblate