Executive brief
Weblate is a web-based translation management platform that integrates with version control systems like Git and Mercurial. The vulnerability allows users to inject commands through unsanitized arguments, potentially enabling attackers to execute arbitrary code or alter repository behavior when creating new translation components.
Technical details
The vulnerability stems from improper neutralization of special elements in command arguments passed to Git and Mercurial (CWE-77, CWE-88). When untrusted users create new components, their input is insufficiently sanitized before being used in shell commands. An authenticated attacker can exploit this to inject malicious arguments that modify the behavior of Git/Mercurial, leading to information disclosure, integrity violations, or potential code execution. The issue was patched in version 4.11.1 with commits 35d59f1 and d83672a. Instances where untrusted users cannot create components are not affected.
Affected products
- Weblate Weblate <4.11.1 (all versions from 1.0 to 4.11.0)
CVE identifiers
- CVE-2022-24727
- CVE-2022-23915
Timeline
- 2022-03-04: disclosed
- 2022-03-04: patched: Fixed in version 4.11.1