CVE-2025-58352 – Weblate has long session expiry times during second factor verification

The following table lists the changes that have been made to the
CVE-2025-58352 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution
of a vulnerability, and for identifying the most recent changes that may
impact the vulnerability’s severity, exploitability, or other characteristics.

  • New CVE Received
    by [email protected]

    Sep. 05, 2025

    Action Type Old Value New Value
    Added Description Weblate is a web based localization tool. Versions lower than 5.13.1 contain a vulnerability that causes long session expiry during the second factor verification. The long session expiry could be used to circumvent rate limiting of the second factor. This issue is fixed in version 5.13.1.
    Added CVSS V4.0 AV:N/AC:H/AT:P/PR:L/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
    Added CWE CWE-613
    Added Reference https://github.com/WeblateOrg/weblate/commit/0b46fe596231dd456283ead66699ae5516f23908
    Added Reference https://github.com/WeblateOrg/weblate/pull/16002
    Added Reference https://github.com/WeblateOrg/weblate/security/advisories/GHSA-377j-wj38-4728
Share the Post:

Related Posts