关键漏洞信息 漏洞标题 Exposure of personal IP address via e-mail 影响版本 Affected versions: <5.12 修复版本 Patched versions: 5.12 描述 Impact: The audit log notifications included the full IP address of the acting user. This could be obtained by third-party servers such as SMTP relays, or spam filters. 修复措施 Patches: This issue has been addressed in Weblate 5.12 via #15102. 参考资料 References: Thanks to micael1 for reporting this issue at HackerOne. 严重性 Severity: Low (2.1 / 10) CVSS v4 基本指标 Exploitability Metrics: - Attack Vector: Network - Attack Complexity: High - Attack Requirements: None - Privileges Required: High - User Interaction: None Vulnerable System Impact Metrics: - Confidentiality: None - Integrity: None - Availability: None Subsequent System Impact Metrics: - Confidentiality: Low - Integrity: None - Availability: None CVE ID CVE-2025-49134 弱点 Weaknesses: CWE-359 致谢 Credits: - amCap1712 (Remediation reviewer) - nijel (Remediation developer)