취약점 및 사고 처리

Product vulnerability reports

더 보기

AI를 사용하여 Weblate의 보안 문제를 발견한 경우 AI를 사용하여 이슈 작성하기 를 읽어주세요.

Weblate의 개발팀은 보안 관련 문제점을 책임감 있게 보고하고 공개하기 위해 최선을 다하고 있습니다. 당사는 Weblate에 적시에 보안 업데이트를 제공하기 위한 정책을 채택하고 이에 따릅니다.

Product vulnerability reports cover security issues in Weblate source code, release artifacts, and documented Weblate security properties. They do not replace operational incident response for a particular deployment.

Reports concerning the separately distributed Weblate Client (wlc) are evaluated against the wlc threat model, which documents its intended trust boundaries, supported security properties, and explicit non-goals.

Weblate의 대부분의 일반 버그는 공개 GitHub 이슈 트래커 에 보고되지만, 보안 문제의 민감한 특성으로 인해 이와 같은 방식으로 공개 보고하지 않도록 요청합니다.

대신 Weblate에서 보안에 영향을 미치는 것을 발견했다고 생각되면 security@weblate.org, GitHub, 또는 HackerOne 을 사용하여 문제점에 대한 설명을 제출해 주세요.

Self-hosted operators should use this process when they believe an incident in their own deployment is caused by a Weblate product vulnerability. Local containment, recovery, customer notification, provider escalation, and other deployment-specific incident response remain the operator’s responsibility.

A member of the security team will respond to you within 48 hours, and depending on what action is taken, you may get more follow-up emails. Suspected active exploitation and severe security incidents receive immediate internal attention under Incident reporting. Acknowledging a report or completing an investigation does not postpone reporting deadlines.

참고

암호화된 보고서 전송

암호화된 이메일을 보내려면 (선택 사항) ID 8EA7 6E43 0976 3323 C2E3 D5A0 C472 9F23 8A80 EA93security@weblate.org 공개 키를 사용해 주세요.

이 공개 키는 가장 일반적으로 사용되는 키 서버에서 사용할 수 있으며, WKD를 사용하거나 weblate.org에서 직접 확인할 수 있습니다.

힌트

Weblate depends on third-party components for many things. In case you find a vulnerability affecting one of those components in general, please report it directly to the respective project. If it also affects a shipped Weblate artifact or a Weblate deployment, report that impact to Weblate through the private channels above.

일부는 다음과 같음:

Weblate-operated service incidents

Operational incidents affecting Hosted Weblate, Dedicated Weblate, or other deployments operated by Weblate s.r.o. are handled using Weblate 사고 대응 계획.

When such an incident also involves a Weblate product vulnerability, the vulnerability report and public advisory follow the product vulnerability reporting process and 취약점 공개 정책 on this page.

Self-hosted deployment incidents

Operators of self-hosted Weblate deployments are responsible for their local incident response process, including containment, recovery, notification, and provider-specific escalation. The Weblate-operated Weblate 사고 대응 계획 can be used as a reference, but it is not a maintained incident response plan for third-party deployments.

If a self-hosted incident appears to be caused by a Weblate product vulnerability, report it using the product vulnerability reporting process above.

취약점 공개 정책

Weblate publishes a security advisory alongside a release containing a vulnerability fix at https://github.com/WeblateOrg/weblate/security/advisories. Advisories identify affected versions, impact, severity, and steps users can take to remediate the vulnerability.

Technical details may be delayed when publishing them would create greater security risks than benefits while users apply the fix. The incident handler records the reason and a review date in the private incident note. This does not delay authority reports or protective advice users need.

Authority reporting

Weblate adopts the following reporting timelines as a voluntary policy baseline for actively exploited Weblate product vulnerabilities and severe product-security incidents. This includes affected shipped dependencies and incidents learned about through self-hosted deployments. Severe security incidents affecting Weblate-operated services also follow this baseline.

Report

Deadline

Early warning

Without undue delay, within 24 hours of awareness.

Main notification

Without undue delay, within 72 hours of awareness.

Final report for an actively exploited vulnerability

Within 14 days after a corrective or mitigating measure becomes available.

Final report for a severe incident

Within one calendar month after the main incident notification.

Hours include weekends and holidays. Acknowledgment, incident declaration, handover, or completion of an investigation does not restart these clocks. When an event involves both active exploitation and a severe incident, track both reporting obligations and final-report deadlines.

These timelines follow the European Commission reporting guidance. The incident handler records whether mandatory or voluntary reporting applies and uses the corresponding route. For CRA reporting, the Single Reporting Platform routes notifications to the coordinating CSIRT and ENISA. This policy does not determine Weblate’s regulatory role or claim compliance; see Product and contact information.

For classification, submission steps, and private incident records, see Incident reporting.

User notifications

Weblate informs impacted users of active exploitation or severe security incidents without undue delay, including available mitigations and corrective actions. Where appropriate, warnings address all users. Known affected contacts, including Hosted and Dedicated Weblate customers, receive e-mail notifications. Public GitHub security advisories provide warnings and updates for self-hosted users whose contact details are not known.

Initial warnings can provide protective advice before a fix or detailed vulnerability disclosure is ready. Authority reporting, user warnings, and publication of technical details proceed separately as needed.

Personal-data breaches also require a separate assessment of notifications to affected individuals, even when there is no active exploitation or severe product-security incident.