Improper Removal of Sensitive Information Before Storage or Transfer
CVE-2025-64326
Summary
Weblate is a web based localization tool. In versions through 5.14, Weblate leaks the IP address of the project member inviting the user to the project in the audit log. The audit log includes IP addresses from admin-triggered actions, which can be viewed by invited users.
- LOW
- NETWORK
- NONE
- UNCHANGED
- REQUIRED
- LOW
- LOW
- NONE
CWE-212 - Improper Removal of Sensitive Information Before Storage or Transfer
The product stores, transfers, or shares a resource that contains sensitive information, but it does not properly remove that information before the product makes the resource available to unauthorized actors.
References
Advisory Timeline
- Published