Weblate 위협 모델

프로젝트: Weblate

Last reviewed for Weblate 2026.10 at commit 8283fcad69f.

Date: 2026-09-01.

Status: Accepted, 2026-09-01.

버전 바인딩: 이 모델은 Weblate 릴리스와 함께 버전이 지정됩니다. Weblate 버전 N에 대한 보고서는 최신 개발 브랜치가 아니라 버전 N용으로 게시된 모델을 기준으로 분류됩니다. (maintainer)

보고 교차 참조: Weblate가 Security properties Weblate provides 에서 주장하는 속성을 위반하는 보고서는 SECURITY.md취약점 및 사고 처리 를 통해 보고합니다. Out of scope 또는 Security properties Weblate does not provide 에 해당하는 보고서는 이 모델이 VALID-HARDENING 으로 라우팅하지 않는 한 이 문서를 인용해 종료할 수 있습니다. (documented) (source: 취약점 및 사고 처리)

출처 범례: *(documented)* 는 해당 주장이 Weblate 문서에 명시되어 있음을 의미합니다. *(maintainer)* 는 이 위협 모델 절차 중 유지관리자가 밝힌 내용임을 의미합니다. *(inferred)* 는 현재 프로젝트 형태에서 추론했으며 유지관리자 확인이 필요함을 의미합니다.

Provenance summary: 118 documented / 71 maintainer / 0 inferred claims.

Weblate는 Django 기반 웹 현지화 플랫폼입니다. 브라우저 사용자, API 클라이언트, 프로젝트 범위 토큰, 저장소 웹훅, VCS 저장소, 백업 아카이브, 백그라운드 워커, 구성된 외부 서비스로부터 작업을 받아 데이터베이스, 데이터스토어, 로컬 파일시스템 저장소, 외부 코드 호스팅 시스템을 통해 번역 프로젝트를 저장하고 동기화합니다. (documented) (source: Weblate 문서, Weblate의 REST API, 지속적 현지화)

범위 및 의도한 사용

구성요소 계열

대표 표면

프로세스 외부 효과

모델 상태

웹 UI 및 REST API

브라우저 보기, 양식, 세션 엔드포인트, Weblate의 REST API

데이터베이스, 데이터스토어, 이메일, 로그, 업로드된 파일

범위 안. (documented) (source: Weblate의 REST API, 설정 지침)

Project translation metrics

GET /api/projects/(string:project)/metrics/ in JSON, CSV, and OpenMetrics formats

Database and statistics-cache reads, including possible lazy cache population

In scope as a read-only public API. Unauthenticated callers can query public projects; private projects and restricted components remain permission-filtered. (documented) (source: Weblate의 REST API, 접근 제어)

Stored translation reports

Report forms and GET /api/reports/ endpoints

Database snapshots and background tasks

In scope as authenticated, permission-checked contributor data with operator-configured retention. The selected report scope is the authorization boundary, including private projects and restricted components below it. (documented) (source: 번역 진행 보고, Weblate의 REST API)

인증, 세션, 권한 부여

로그인, 2FA, SSO, 팀, 권한, 프로젝트 접근, API 토큰

데이터베이스, 신원 제공자, 브라우저 쿠키

범위 안. (documented) (source: 인증, 접근 제어)

프로젝트 범위 API 토큰

프로젝트 API access 에서 생성된 토큰

토큰 권한이 허용하는 것과 같은 애플리케이션 효과

위임된 프로젝트 범위가 있는 인증된 행위자로서 범위 안. (documented) (source: Weblate의 REST API, 접근 제어)

웹훅

알림 후크, project 후크 활성화, App webhook URL

백그라운드 작업 예약 및 VCS 저장소 업데이트

In scope as a public, deployment-hardened interface. (documented) (source: 알림 후크, 후크 활성화, App webhook URL)

VCS 통합

Repository URLs, branches, pushes, pulls, merge requests, local clones, and GitHub App registration, connections, component migration, and removal

Filesystem, child VCS commands, SSH/HTTPS network connections, and provider repository or installation state

Weblate 구성이나 프로젝트 콘텐츠를 통해 도달 가능한 경우 범위 안. (documented) (source: 지속적 현지화, Code-hosting integrations)

백그라운드 작업

Celery queues for repository updates, project deletion, notifications, translation memory, translation, and backups

데이터베이스, 데이터스토어, 파일시스템, 아웃바운드 네트워크

In scope as Weblate-controlled execution of user or operator actions. (documented) (source: 설정 지침, Weblate의 REST API)

프로젝트 백업 가져오기/내보내기

프로젝트 수준 백업, Weblate의 REST API project backup endpoints, import_projectbackup

Uploaded ZIP archives, generated backup archives, filesystem restore, repository state

In scope. (documented) (source: Weblate 백업 및 이전, Weblate의 REST API, 관리 명령어)

서비스 백업

BorgBackup 구성 및 backup

파일시스템 또는 SSH를 통한 로컬 또는 원격 백업 저장소

구성된 백업 작업을 Weblate가 처리하는 부분은 범위 안입니다. Borg 자체는 범위 밖입니다. (documented) (source: Weblate 백업 및 이전, 관리 명령어)

기계 번역 및 아웃바운드 통합

Machine translation, avatars, status reporting, telemetry, error reporting, VCS hosts, GitHub App connections, CDN add-on, Fedora Messaging add-on, e-mail delivery (SMTP or AWS SES)

Outbound HTTP(S), AMQP(S), provider APIs, logs

In scope for Weblate’s enforcement of configured access and network restrictions. Provider behavior is out of scope. (documented) (source: 설정, Code-hosting integrations, 애드온)

애드온

기본 제공 애드온 및 관리자가 구성한 애드온 실행

Varies by add-on; can mutate project or repository state or contact services

기본 제공 애드온은 활성화된 경우 범위 안입니다. 서드파티 애드온은 Weblate의 권한 및 설치 관문을 제외하고 범위 밖입니다. (maintainer)

관리 명령어

운영자가 실행하는 weblate 명령

데이터베이스, 파일시스템, VCS, 백업 저장소

신뢰할 수 없는 Weblate 데이터를 처리할 때 범위 안입니다. 로컬 운영자 셸은 신뢰됩니다. (maintainer)

테스트, 생성된 문서, 스크린샷, 개발 픽스처

docs/_build/, docs/screenshots/, 테스트, 로컬 픽스처

개발 전용 파일 및 생성된 산출물

제품 보안 주장에서는 범위 밖. (maintainer)

The local application QA profile runs development Weblate and workers with known development credentials. Its application and mailbox ports are dynamically allocated and bound to IPv4 loopback; PostgreSQL, Valkey, and SMTP are not published. Test and application profiles use separate storage and networks within a checkout-specific Compose project. Worktrees still share host Git metadata and the Docker daemon: this provides development-state separation, not a boundary against a malicious checkout or local user. This profile is not a supported production deployment. (maintainer)

The intended deployment is a server-side Weblate installation behind a web server or reverse proxy, with a WSGI or ASGI application server, PostgreSQL database, datastore, Celery workers, a writable data directory, and optional outbound VCS, backup, identity-provider, and machine-translation integrations. (documented) (source: 설정 지침)

The WSGI and ASGI deployment modes expose the same Django HTTP request surface and rely on the same reverse-proxy controls. ASGI deployment does not add a WebSocket interface. (documented) (source: Sample configuration to start Granian with ASGI)

관련 행위자는 신뢰 수준에 따라 인증되지 않은 클라이언트, 인증된 사용자, 검토자, 프로젝트 관리자, 관리자, 프로젝트 범위 API 토큰, 웹훅 발신자, 외부 VCS 제공자, 구성된 외부 서비스, 로컬 운영자로 나뉩니다. (documented) (source: 접근 제어, Weblate의 REST API)

Weblate는 프로세스 내부 보안 라이브러리로 임베드하거나, 신뢰할 수 없는 코드의 샌드박스로 사용하거나, 프로덕션 사용을 위해 문서화된 배포 제어 없이 노출하도록 의도되지 않았습니다. (maintainer)

범위 밖

다음은 이 모델의 명시적 비목표입니다:

  • 손상된 운영 체제 계정, 컨테이너 런타임, 데이터베이스 서버, 데이터스토어, 리버스 프록시 또는 관리자 셸. Weblate는 이러한 경계 안에서 실행되며, 이미 손상된 호스트로부터 자신을 보호한다고 주장하지 않습니다. (maintainer)

  • 제한 없는 서버 접근 권한을 가진 악의적 Weblate 사이트 관리자 또는 로컬 운영자. 이러한 행위자는 설정, 자격 증명, 데이터, 코드를 변경할 수 있습니다. (maintainer)

  • 독립 프로젝트로서의 서드파티 의존성 취약점. 일반 Django, Django REST framework, Python Social Auth, BorgBackup, VCS, 데이터베이스, 제공자 취약점은 Weblate의 사용 방식에 문제가 있는 경우가 아니라면 업스트림에 보고합니다. (documented) (source: 취약점 및 사고 처리)

  • 액션 고정, 산출물 서명, 의존성 최신성, 저장소 브랜치 보호를 포함한 빌드 및 릴리스 위생. 이는 프로젝트 운영에 영향을 주지만 Weblate 런타임 동작에 대한 위협 모델 주장은 아닙니다. (maintainer)

  • 외부 VCS 제공자, 신원 제공자, 메일 서버, 기계 번역 서비스, 아바타 서비스, CDN 저장소 또는 백업 저장소의 일반 보안. Weblate는 이들과의 구성된 상호작용만 모델링합니다. (maintainer)

  • Weblate 밖에서 이루어지는 사용자 조직의 번역 공급망 선택. 외주 또는 크라우드소싱 번역자 위험은 현지화 위협 모델 에 별도로 설명되어 있습니다. (documented) (source: 현지화 위협 모델)

  • 서드파티 애드온 코드, 로컬 사용자 정의 코드, 개발 픽스처, 생성된 문서 출력, 테스트 전용 코드, 데모 또는 예제 데이터. (maintainer)

신뢰 경계 및 데이터 흐름

Weblate의 기본 신뢰 경계는 네트워크에 노출되는 애플리케이션 표면입니다. 브라우저 보기, API 엔드포인트, 웹훅 엔드포인트, 업로드 엔드포인트가 덜 신뢰되는 행위자로부터 데이터를 받아 데이터베이스 행, 로컬 저장소 상태, 백그라운드 작업, 아웃바운드 요청, 렌더링된 UI로 변환합니다. (maintainer)

경계

신뢰 전환

클라이언트 브라우저/API 클라이언트에서 Weblate로

신뢰할 수 없거나 인증된 요청은 권한 검사를 거친 애플리케이션 작업이 됩니다. (documented) (source: Weblate의 REST API, 접근 제어)

Weblate request process to repository Celery worker

Permission-checked browser and API repository actions become queued work carrying the initiating user and affected repository scope. The worker reacquires the datastore reservation and rechecks the user’s current VCS permission across the current linked-component scope before mutation. The broker, datastore, and workers are trusted parts of the same Weblate instance. (maintainer)

웹훅 발신자에서 Weblate로

Public forge notifications can schedule repository synchronization where hooks are enabled, matching components by exact repository URL rather than host or path suffix fallback. Generic hook responses expose match counts and, for updated components, project/component slugs and API URLs, including for private projects and restricted components. Components managed through an authenticated integration are excluded from generic matching and diagnostics; currently this applies to the GitHub App VCS backend. Registered GitHub App webhooks authenticate with a per-app URL token and GitHub signature verification. Opt-in legacy GitHub App deliveries to the generic GitHub webhook URL authenticate with a separately configured secret. (documented) (source: 알림 후크, 후크 활성화, Matching webhook targets, App webhook URL, GITHUB_LEGACY_APP_WEBHOOK_SECRET)

Weblate에서 데이터베이스/데이터스토어로

권한 검사를 거친 애플리케이션 상태는 영구 데이터와 대기열 작업이 됩니다. (documented) (source: 설정 지침)

Weblate에서 로컬 VCS 저장소로

프로젝트 구성과 저장소 콘텐츠가 파일시스템 및 VCS 작업을 구동합니다. (documented) (source: 지속적 현지화)

Weblate에서 외부 서비스로

구성된 URL, 자격 증명, 제공자 설정이 아웃바운드 네트워크 연결을 구동합니다. (documented) (source: Code-hosting integrations, 설정)

Project backup archives and Weblate filesystem

Uploaded ZIP members and metadata become restored project state; generated project backups are written to and read from local backup storage. (documented) (source: Weblate 백업 및 이전, Weblate의 REST API, 프로젝트 수준 백업)

도달 가능성 전제조건:

  • 웹 UI 또는 API 발견 사항은 인증되지 않은 클라이언트, 인증된 사용자, 프로젝트 범위 토큰이 문서화된 라우트, 양식 또는 API 엔드포인트를 통해 도달할 수 있을 때만 모델 안에 있습니다. (maintainer)

  • A project-metrics finding is in model when the response includes a project or component the caller cannot access, or exposes data beyond the documented component and language identifiers, aggregate translation statistics, and statistics update timestamps. Unauthenticated access to these aggregates for public projects is intentional. (documented) (source: Weblate의 REST API, 접근 제어)

  • 권한 부여 발견 사항은 문서화된 권한, 팀, 프로젝트, 구성요소, 언어, 용어집, 토큰 또는 사이트 전체 경계를 넘을 때만 모델 안에 있습니다. (documented) (source: 접근 제어)

  • A webhook finding is in model only when a request can reach an enabled hook endpoint and affect repository update scheduling, task volume, or information returned to the caller beyond the documented matching diagnostics. (documented) (source: 알림 후크, 후크 활성화, Matching webhook targets)

  • VCS 발견 사항은 공격자가 제어하거나 덜 신뢰되는 저장소 데이터, 브랜치 이름, URL, 파일 이름, 커밋 메타데이터 또는 프로젝트 구성이 Weblate의 VCS 작업에 영향을 줄 수 있을 때만 모델 안에 있습니다. (maintainer)

  • 백업 가져오기 발견 사항은 Weblate를 통해 업로드되었거나 import_projectbackup 에 제공된 프로젝트 백업에서 도달 가능한 경우에만 모델 안에 있습니다. (documented) (source: 프로젝트 수준 백업, import_projectbackup)

  • A backup export finding is in model only when reachable from documented project backup creation or download routes, including the REST API for users or project-scoped tokens with project edit permission. (documented) (source: Weblate의 REST API, 프로젝트 수준 백업, 접근 제어)

  • 백그라운드 작업 발견 사항은 범위 안의 Weblate 표면에서 대기열에 추가되거나 예약된 Weblate 유지관리 경로에서 예약될 수 있을 때만 모델 안에 있습니다. (documented) (source: 설정 지침)

  • A stored-report finding is in model when an authenticated user can generate, list, or render contributor data outside the current authorized scope. Creator access applies only to reports containing the creator’s own data (own_data=True) and still requires current access to the selected scope. Full reports require current reports.view permission even for their creator. (documented) (source: 번역 진행 보고, Weblate의 REST API)

  • A user-profile API finding is in model when an authenticated user can read or mutate another user’s profile preferences outside the documented user.view, user.edit, or self-service boundaries. (documented) (source: Weblate의 REST API, 사용자 프로필)

  • 관리 명령 발견 사항은 신뢰할 수 없는 Weblate 데이터가 해당 명령으로 처리될 때만 모델 안에 있습니다. 임의의 로컬 셸 접근은 공격자 능력이 아닙니다. (maintainer)

환경 가정

Weblate는 지원되는 Python 및 Django 런타임, 올바르게 구성된 데이터베이스, 데이터스토어, 쓰기 가능한 데이터 디렉터리, 백그라운드 처리가 필요한 기능을 위한 실행 중인 워커를 가정합니다. (documented) (source: 설정 지침)

프로덕션 배포는 외부 웹 서버 또는 리버스 프록시를 Weblate의 HTTPS, 호스트 헤더, 본문 크기, 프록시 헤더 설정과 일관되게 구성해야 합니다. (documented) (source: 설정 지침, ENABLE_HTTPS, ALLOWED_HOSTS)

데이터베이스, 데이터스토어, 내부 서비스 포트는 신뢰할 수 없는 네트워크에 직접 노출되지 않는다고 가정합니다. (maintainer)

파일시스템 권한은 관련 없는 로컬 사용자가 Weblate의 데이터 디렉터리, 구성, VCS 저장소, 생성된 SSH 래퍼, 백업, 비밀 자료를 수정하지 못하게 한다고 가정합니다. (documented) (source: Weblate 백업 및 이전, 설정 지침)

Celery 워커는 같은 Weblate 인스턴스의 신뢰된 구성요소입니다. 악의적이거나 손상된 워커는 손상된 애플리케이션 프로세스와 같습니다. (maintainer)

Docker’s combined, split, and single Celery worker modes change how task queues and concurrency are distributed among worker processes. (documented) (source: CELERY_WORKER_MODE) These modes do not create security isolation between queues; every worker retains the same trusted application authority. Resource contention, throughput, and task latency differences between modes are deployment-sizing and availability concerns. (maintainer)

VCS command execution, SSH, and HTTPS clients are assumed to execute as the Weblate service user with the credentials configured for the relevant project or integration, including database-stored GitHub App credentials used for installation tokens and webhook signature verification. (documented) (source: Code-hosting integrations, SSH_EXTRA_ARGS)

Weblate가 호스트에 하는 일:

  • It opens outbound network connections for configured VCS, identity-provider, avatar, machine-translation, backup, status-reporting, telemetry, error-reporting, and add-on features such as outbound webhooks and Fedora Messaging AMQP delivery. (documented) (source: 설정, Code-hosting integrations, Weblate 백업 및 이전)

  • 저장소 및 백업 워크플로의 일부로 VCS 및 백업 관련 도우미 명령을 실행합니다. (documented) (source: 지속적 현지화, Weblate 백업 및 이전)

  • 구성된 데이터 디렉터리, 저장소 스토리지, 미디어/글꼴, 백업 덤프, 로그, 캐시 위치에 씁니다. (documented) (source: 설정, Weblate 백업 및 이전)

  • It sends e-mail and notifications when configured to do so. When django_ses.SESBackend is selected, outbound e-mail is delivered over HTTPS to the configured AWS SES regional endpoint (email.<region>.amazonaws.com by default, overridable via WEBLATE_AWS_SES_REGION_ENDPOINT); the endpoint is operator-controlled trusted infrastructure and is not subject to private-target restrictions. (documented) (source: 설정, Docker를 사용한 설치)

  • 로깅, 캐시 쓰기, 하위 프로세스 실행, 아웃바운드 네트워크 접근 같은 프로세스 전체 부작용이 없다고 주장하지 않습니다. (maintainer)

빌드 시점 및 구성 변형

조정 항목

기본 또는 문서화된 태세

모델에 미치는 영향

유지관리자 입장

ENABLE_HOOKS후크 활성화

익명 원격 훅은 구성 가능하며 프로젝트에서도 활성화되어야 합니다. (documented)

웹훅 엔드포인트를 공개 예약 인터페이스로 노출합니다. 악용 저항성은 배포 제어에 따라 달라집니다. (documented) (source: 알림 후크, 후크 활성화)

훅을 노출하는 프로덕션 배포는 리버스 프록시 속도 제한, 본문 크기 제한, 모니터링, 최소한의 공개 노출을 사용합니다. (maintainer)

ENABLE_HTTPS, 프록시 SSL 헤더, HSTS 설정

HTTPS는 보안 쿠키, 리다이렉트, HSTS, WebAuthn, 생성된 URL에 영향을 줍니다. (documented) (source: ENABLE_HTTPS)

HTTPS를 비활성화하거나 잘못 구성하면 Weblate가 브라우저 보안에 의존하는 전송 및 쿠키 보호가 제거됩니다. (documented) (source: ENABLE_HTTPS)

문서화된 프로덕션 태세는 올바른 프록시 헤더를 갖춘 HTTPS입니다. (documented)

ALLOWED_HOSTS

허용되는 HTTP 호스트명을 구성합니다. (documented) (source: ALLOWED_HOSTS)

광범위한 호스트 허용은 호스트 헤더 기반 보호와 URL 생성 가정을 약화할 수 있습니다. (maintainer)

프로덕션 배포는 이를 인스턴스 호스트명으로 제한합니다. (maintainer)

CELERY_WORKER_MODE

Docker defaults to one combined prefork worker for all queues. Split mode uses queue-specific workers, while single mode uses one solo worker. (documented) (source: Docker를 사용한 설치)

Changes worker process topology, concurrency, and queue contention, but not worker trust or application authority. (maintainer)

Queue-specific workers provide operational isolation and independent tuning, not a security boundary. Operators choose a mode based on memory, capacity, and availability requirements. (maintainer)

WEBLATE_API_RATELIMIT_ANON, WEBLATE_API_RATELIMIT_USER, API_RATELIMIT_USER_OVERRIDES, API_RATELIMIT_IP_OVERRIDES, RATELIMIT_ATTEMPTS, and RATELIMIT_GITHUB_SETUP_ATTEMPTS

속도 제한은 구성 가능합니다. (documented) (source: Weblate의 REST API, 설정)

가용성 주장은 배포 규모와 노출에 적합한 속도 제한을 가정합니다. (maintainer)

Operators can override or exempt users and IP networks, including anonymous clients. IP exemptions rely on trusted proxy configuration; they do not grant authentication or permissions. (documented) (source: API 속도 제한, IP_BEHIND_REVERSE_PROXY). Disabling rate limits changes DoS triage from Weblate bug to deployment posture unless a single request violates a claimed property. (maintainer)

CSP_SCRIPT_SRC, CSP_IMG_SRC, CSP_CONNECT_SRC, CSP_STYLE_SRC, CSP_FONT_SRC, CSP_FORM_SRC

Content Security Policy sources are configurable. (documented) (source: 설정) The default script policy permits inline execution only on explicitly scoped compatibility paths. (maintainer)

소스를 넓히면 XSS 또는 서드파티 콘텐츠에 대한 브라우저 측 격리가 줄어들 수 있습니다. (maintainer)

서드파티 소스를 추가하는 배포는 확장된 브라우저 신뢰를 수용합니다. (maintainer)

PROJECT_BACKUP_UPLOAD_MAX_SIZE, PROJECT_BACKUP_IMPORT_MAX_MEMBERS, PROJECT_BACKUP_IMPORT_MAX_TOTAL_UNCOMPRESSED_SIZE, PROJECT_BACKUP_IMPORT_MAX_COMPRESSED_ENTRY_SIZE, PROJECT_BACKUP_IMPORT_MIN_RATIO_SIZE, PROJECT_BACKUP_IMPORT_MAX_COMPRESSED_ENTRY_RATIO

기본값은 프로젝트 백업 업로드 및 가져오기 크기, 구성원 수, 의심스러운 압축 비율에 한계를 둡니다. (documented) (source: 설정)

이 제한을 높이거나 비활성화하면 복원 시점의 리소스 노출이 확대됩니다. (documented) (source: 설정)

위에 문서화된 기본값은 백업 가져오기 리소스 보장의 일부입니다. (documented)

아웃바운드 URL용 비공개 대상 제한 및 허용목록

User-configurable outbound URL surfaces documented with private-target restriction settings reject internal or non-public targets by default. (documented) (source: ASSET_RESTRICT_PRIVATE, PROJECT_WEB_RESTRICT_PRIVATE, WEBHOOK_RESTRICT_PRIVATE, VCS_RESTRICT_PRIVATE) Protected direct HTTP requests are bound to addresses approved by runtime validation; configured per-protocol HTTP proxies are trusted infrastructure and resolve their destination hosts. Protected Git HTTPS and SSH operations are bound to addresses approved by runtime validation. Protected SSH operations validate the effective HostName and Port. Trusted administrator SSH configuration can alter routing, and SSH_EXTRA_ARGS can override connection binding. Permanent same-host Git HTTP redirects are probed without automatic redirect following. Every direct destination is independently validated and bound before use; configured per-protocol HTTP proxies use the shared trusted outbound routing. Git LFS object transfers are disabled and outside the supported VCS integration surface. VCS clients without connection binding require an explicit trusted-host exemption. (maintainer)

Allowlist settings and privileged configuration can intentionally expand reachability. A non-empty VCS_ALLOW_HOSTS also restricts all configured VCS hosts, while VCS_PRIVATE_ALLOWLIST only exempts matching hosts from private-target checks and does not bypass that host filter. Fedora Messaging broker URLs are site-administrator configuration and are trusted by this model. (documented) (source: ASSET_PRIVATE_ALLOWLIST, PROJECT_WEB_RESTRICT_ALLOWLIST, WEBHOOK_PRIVATE_ALLOWLIST, VCS_ALLOW_HOSTS, VCS_PRIVATE_ALLOWLIST)

기본 비공개 대상 거부는 문서화된 사용자 구성 가능 URL 표면에 대한 애플리케이션 수준 보안 속성입니다. (maintainer)

SSH_EXTRA_ARGS

사용자 정의 SSH 옵션을 허용합니다. (documented) (source: SSH_EXTRA_ARGS)

Weakening SSH algorithms or host verification changes VCS transport assumptions. Routing options can override protected repository address pinning. (maintainer)

운영자는 사용자 정의 SSH 옵션의 보안 영향을 책임집니다. (maintainer)

AWS SES e-mail backend

Activated by setting WEBLATE_EMAIL_BACKEND to django_ses.SESBackend in Docker deployments. (documented) (source: Docker를 사용한 설치)

Weblate opens an outbound HTTPS connection to the configured SES regional endpoint to deliver e-mail. AWS credentials are read from the boto3 credential chain (environment variables, IAM role, or credential file). The SES endpoint and credentials are operator-controlled trusted infrastructure. (maintainer)

Operators are responsible for securing AWS credentials, choosing an appropriate SES region and endpoint, and ensuring that the boto3 credential chain does not expose credentials beyond the intended scope. (maintainer)

서드파티 애드온 및 로컬 사용자 정의

관리자는 동작을 확장할 수 있습니다. (documented) (source: 애드온)

사용자 정의 코드는 이 모델 밖의 새 신뢰 경계와 보안 속성을 추가할 수 있습니다. (maintainer)

서드파티 코드는 별도로 모델링됩니다. (maintainer)

입력 가정

표면

입력

공격자가 제어 가능?

호출자 또는 운영자가 적용해야 함

브라우저 양식 및 REST API

요청 본문, 쿼리 문자열, 업로드된 파일, 헤더, 쿠키

예, 행위자의 인증 상태 안에서 가능합니다. (documented) (source: Weblate의 REST API)

HTTPS, 올바른 호스트/프록시 구성, 속도 제한, 권한 할당. (documented) (source: 설정 지침, 접근 제어)

인증 엔드포인트

비밀번호, WebAuthn 데이터, SSO 콜백, 재설정 토큰

예. (documented) (source: 인증)

올바른 신원 제공자 구성 및 HTTPS. (documented) (source: 인증, ENABLE_HTTPS)

프로젝트 범위 토큰

토큰으로 인증된 API 요청

예, 토큰을 보유한 누구든 가능합니다. (documented) (source: Weblate의 REST API)

토큰 저장, 순환, 최소 권한 팀 멤버십. (maintainer)

번역 콘텐츠

Source strings, translations, comments, suggestions, glossary entries; suggestion API requests including rejection_reason text, is_spam flag, and approve flag

예, 관련 권한이 있는 사용자 또는 가져온 저장소에서 가능합니다. (documented) (source: Weblate를 사용한 번역, 접근 제어)

Review workflows for project-specific content integrity; approving a suggestion via the API additionally requires the unit.review permission check to be satisfied. (documented) (source: 번역 워크플로, Weblate의 REST API)

User profile API

Nested profile object on GET /api/users/(str:username)/, PUT /api/users/(str:username)/, and PATCH /api/users/(str:username)/, including language and project watch preferences, dashboard component list selection, and commit or public e-mail choices

Yes, for authenticated users updating their own profile or actors with user.edit. (documented) (source: Weblate의 REST API, 사용자 프로필)

Assign user.edit only to trusted administrators; self-service profile e-mail fields accept only verified addresses, watched projects are limited to accessible projects, and dashboard component lists are limited to lists the user is allowed to use. (documented) (source: Weblate의 REST API)

웹훅 엔드포인트

헤더, 이벤트 유형, 본문, 저장소 및 브랜치 메타데이터

예, 엔드포인트에 도달 가능한 경우입니다. (documented) (source: 알림 후크)

필요한 곳에서만 훅 활성화, 요청 제한, 모니터링. (maintainer)

GitHub App lifecycle

Registration and installation callbacks, GitHub OAuth code, signed Weblate state, installation ID, account metadata, component migration selections, and connection-removal requests

Yes, from authenticated Weblate users and GitHub redirect query strings. (documented) (source: Registering the GitHub App from Weblate, Migrating existing components)

Registering App credentials requires the site-wide management.configure permission. Connecting or removing an installation requires management rights for its workspace, and Weblate verifies GitHub administration of an installation before connecting it. Component migration additionally requires edit permission for every selected component. Removing the last workspace connection also attempts to uninstall the App from GitHub. (documented) (source: Registering the GitHub App from Weblate, Migrating existing components)

저장소 구성

Repository URLs, branches, push URLs, credentials, Gerrit review push options, add-on settings, and Version control parameters controlling force pushes and pull-request behavior

해당 관리 권한이 있는 사용자에게 신뢰됩니다. (documented) (source: 접근 제어, 지속적 현지화)

VCS 및 프로젝트 관리 권한은 신뢰할 수 있는 사용자에게만 할당하세요. (documented) (source: 접근 제어)

외부 저장소 콘텐츠

번역 파일, 경로, 브랜치 이름, 커밋 메타데이터

예, 업스트림 저장소가 다른 행위자에게 제어되는 경우입니다. (maintainer)

구성된 업스트림 저장소를 신뢰하거나 가져온 변경 사항을 검토하세요. (maintainer)

프로젝트 백업 가져오기

ZIP 아카이브 구성원, 메타데이터, 번역 파일, 저장소 상태

예, 백업을 업로드하거나 제공할 수 있는 누구에게나 가능합니다. (documented) (source: 프로젝트 수준 백업)

가져오기 제한을 인스턴스에 적합한 값으로 유지하세요. (documented) (source: 설정)

Project backup export

Backup creation requests and requested backup file names

Yes, for users or project-scoped tokens with project edit permission. (documented) (source: Weblate의 REST API, 프로젝트 수준 백업, 접근 제어)

Grant project edit permission only to trusted project administrators. (documented) (source: 접근 제어)

기계 번역 및 외부 서비스 구성

제공자 URL, 자격 증명, 모델 또는 서비스 설정

관리자 또는 구성 권한을 부여받은 사용자에게 신뢰됩니다. (documented) (source: 자동 제안, 접근 제어)

구성된 제공자를 그들에게 전송되는 데이터의 수신자로 취급하세요. 제출되는 콘텐츠는 제공자와 활성화된 기능에 따라 달라집니다. (maintainer)

관리 명령어

로컬 운영자가 제공한 명령줄 인자 및 파일

Weblate 데이터 또는 프로젝트 백업을 처리하는 경우가 아니라면 신뢰된 로컬 입력입니다. (maintainer)

셸 접근은 신뢰할 수 있는 운영자로 제한하세요. (maintainer)

크기 및 속도 가정:

  • Weblate는 큰 HTTP 요청에 대해 애플리케이션 및 리버스 프록시 업로드 제한에 의존합니다. (documented) (source: PROJECT_BACKUP_UPLOAD_MAX_SIZE)

  • 프로젝트 백업 가져오기는 구성원 수, 총 비압축 크기, 압축된 항목 크기, 최소 비율 크기, 압축률 설정으로 제한됩니다. (documented) (source: 설정)

  • Project backup metadata, object references, repository paths, outbound URLs, regular expressions, and screenshot content are validated before restore writes project state. Failed restores remove repository and media objects created by that attempt. (documented) (source: 프로젝트 수준 백업)

  • API 및 일부 웹 작업은 구성된 속도 제한으로 보호되어야 합니다. (documented) (source: Weblate의 REST API, 설정)

  • Project metrics response size and request work scale with the number of visible components and translations and with statistics-cache state. Cache misses can calculate and store translation statistics. The endpoint relies on standard API rate limits and deployment sizing rather than a separate fixed project-size limit. (documented) (source: Weblate의 REST API, 설정)

  • 저장소 크기, 프로젝트 수, 구성요소 수, 워커 용량은 단일 범위 내 입력이 문서화된 제한이나 권한을 우회하지 않는 한 배포 규모 산정 문제입니다. (maintainer)

공격자 모델

행위자

범위 내 능력

범위 밖 능력

인증되지 않은 인터넷 클라이언트

공개 페이지, 등록, 로그인, API, 도달 가능한 웹훅 엔드포인트로 HTTP(S) 요청을 보냅니다. (documented) (source: Weblate의 REST API)

서버 메모리 읽기, 리버스 프록시 제어 우회, 내부 서비스 직접 접근. (maintainer)

인증된 사용자

할당된 팀, 권한, 워크플로가 허용하는 작업을 수행합니다. (documented) (source: 접근 제어)

Weblate 결함을 악용하지 않고 할당된 권한 밖에서 행동합니다. (documented) (source: 접근 제어)

검토자 또는 프로젝트 관리자

위임된 프로젝트, 구성요소, 언어, 검토, VCS, 번역 메모리, 스크린샷 또는 접근 관리 권한을 행사합니다. (documented) (source: 접근 제어)

해당 역할이 부여되었거나 Weblate 결함을 악용하지 않는 한 사이트 관리자가 됩니다. (maintainer)

프로젝트 범위 API 토큰 보유자

Use API permissions assigned to the token’s team memberships, including project backup creation and download where project edit permission is granted. (documented) (source: Weblate의 REST API, 접근 제어, 프로젝트 수준 백업)

범위 밖의 프로젝트, 구성요소 또는 사이트 전체 기능에 접근합니다. (documented) (source: 접근 제어)

웹훅 발신자

Send forged, replayed, malformed, or high-volume webhook requests to enabled hook endpoints and observe documented matching diagnostics. (documented) (source: 알림 후크, Matching webhook targets)

Weblate가 검증하지 않는 곳에서 포지 인증 신원을 얻습니다. (maintainer)

외부 VCS 또는 서비스 제공자

구성된 통합에 따라 저장소 데이터, API 응답, 리다이렉트 또는 오류를 반환합니다. (documented) (source: Code-hosting integrations)

Weblate가 처리하는 데이터 또는 프로토콜 동작을 통하지 않고 Weblate 호스트를 손상합니다. (maintainer)

번역자 또는 현지화 기여자

다운스트림 애플리케이션이 사용할 수 있는 번역 콘텐츠를 제출합니다. (documented) (source: 현지화 위협 모델)

Weblate 밖에서 다운스트림 애플리케이션의 이스케이프, 렌더링 또는 검토 정책을 제어합니다. (documented) (source: 현지화 위협 모델)

로컬 운영자

관리 명령을 실행하고, 구성을 변경하고, 백업에 접근합니다. (documented) (source: 관리 명령어, Weblate 백업 및 이전)

로컬 악성 운영자는 이 모델에서 신뢰됩니다. (maintainer)

모델링된 공격자는 권한 부여를 우회하거나, 권한 없이 번역 또는 저장소 데이터를 수정하거나, 비공개 프로젝트 또는 사용자 데이터를 공개하거나, 저장소 동기화를 위조 또는 악용하거나, 안전하지 않은 아웃바운드 요청을 유발하거나, Weblate가 제어하는 워크플로를 통해 명령을 실행하거나, 제한된 애플리케이션 리소스를 고갈시키려 합니다. (maintainer)

Weblate가 제공하는 보안 속성

속성

조건

위반 증상

심각도 등급

Web authorization separates site, project, component, language, glossary, VCS, translation memory, screenshot, review, and access management permissions. (documented) (source: 접근 제어, 인증, 번역 메모리)

Permission assignments match the intended trust relationship. Team-level enforced 2FA is satisfied by human users before team-derived permissions apply. Pending authenticator app registrations do not satisfy 2FA requirements. Registration requires a valid TOTP code and can be completed only once, including under concurrent submissions; the registration code is consumed for subsequent authentication. Each account can have at most one pending registration, shared across browser sessions and expiring after 24 hours. (documented) (source: 2단계 인증) Component administrators are trusted to configure operations that can affect repository contents, for example by selecting files through component settings, configuring add-ons, or enabling force pushes and pull-request behavior through Version control parameters. Users with management rights for a workspace are trusted to connect and remove its GitHub App installations; removing the final workspace connection can uninstall the App from GitHub. GitHub App component migration separately requires edit permission for every selected component. Linking a repository extends this trust to administrators of every linked component for the complete shared checkout. Permissions for explicit VCS actions cover every component sharing an affected repository, including linked components in other projects. Project-wide VCS actions omit repositories where this permission check fails; they do not partially operate on an individual shared checkout. Explicit VCS actions queued from the browser or API retain the initiating user, serialize access to the affected repositories, and recheck that user’s permission against the current linked-component scope in the worker before mutation. Weblate’s normal background commit and push of authorized translation changes does not require the editor to have these VCS permissions. The reports.view permission authorizes all report data in the selected scope, including private projects and restricted components below it. Complete workspace-level report access requires two-factor authentication for regular users if any project in the workspace enforces it. Superusers and bot accounts are exempt. Translation memory attributed to an existing restricted component follows that component’s access rules. Unattributed automatic memory, including unmatched legacy entries and memory retained after component removal, follows its remaining translation-memory scope. Private and Custom project engage pages and rendered status widgets follow project access control unless a trusted access manager enables Public sharing. That explicit opt-in publishes project and component names, including restricted components, together with translation statistics, languages, and progress, but does not grant access to project content or APIs.

사용자 또는 토큰이 할당된 범위 밖의 데이터를 읽거나 변경할 수 있습니다.

비공개 데이터 또는 권한 있는 변경이 노출될 때 보안상 중요합니다.

프로젝트 범위 API 토큰은 할당된 프로젝트/팀 권한으로 제한됩니다. (documented) (source: Weblate의 REST API, 접근 제어)

토큰은 신뢰할 수 있는 행위자가 생성하고 저장합니다.

토큰이 프로젝트 또는 팀 범위 밖에서 동작할 수 있습니다.

보안상 중요함.

Authentication and session controls protect browser sessions when HTTPS and proxy settings are correct. Pending second-factor sessions are bound to the current password authentication state, and repeated rejected second-factor submissions lock password sign-in according to AUTH_LOCK_ATTEMPTS. (documented) (source: 인증, ENABLE_HTTPS)

프로덕션 HTTPS 및 보안 쿠키 설정이 활성화되어 있습니다.

Session fixation, credential bypass, cross-user session confusion, or a pending password sign-in remaining usable after a password change or account lock.

보안상 중요함.

Weblate가 렌더링하는 사용자 제공 콘텐츠는 다른 사용자의 브라우저에서 스크립트를 실행하지 않아야 합니다. (maintainer)

콘텐츠는 Weblate UI 템플릿과 표준 이스케이프를 통해 표시됩니다.

Weblate 원본에서 저장형 또는 반사형 XSS.

보안상 중요함.

Weblate가 처리하는 저장소, 브랜치, 경로, VCS 입력은 셸 명령 실행이 되어서는 안 됩니다. (maintainer)

VCS operations are invoked through Weblate-supported repository workflows and configured credentials. Project backup restores allow only non-executable Git, git-svn, and Mercurial repository state, and rebuild repository-local configuration from validated component settings. Weblate does not populate Git submodules (see Git submodules).

명령어 주입 또는 Weblate 사용자로서의 임의 코드 실행.

보안상 중요함.

Private project data other than documented generic webhook matching diagnostics and metadata published through Public sharing, user data, credentials, tokens, SSH keys, and 2FA secrets are not disclosed to actors lacking permission. (documented) (source: 접근 제어, 개인정보 보호 규정 준수, 버전 관리 통합)

Host, database, and storage permissions are intact. Generic webhook responses expose only the match counts, project/component slugs, and API URLs documented in Matching webhook targets. Public sharing permits unauthenticated access to engage pages and rendered status widgets, exposing project and component names, including restricted components, translation statistics, languages, and progress. It does not grant access to project content or APIs. Repository content deliberately shared through linked components follows the linked repository trust boundary. Project repository permission diagnostics expose the paths of linked components that prevent an operation, but do not expose their content or repository status. Custom add-ons list only non-sensitive fields as public configuration; unlisted values are redacted from public change history.

Cross-project data leak not covered by the documented generic webhook diagnostics, public-sharing metadata, or linked-repository trust boundary, credential exposure, or unauthorized export.

보안상 중요함.

백업 가져오기는 문서화된 업로드, 구성원, 총 크기, 의심스러운 압축 임계값을 초과하는 아카이브를 거부합니다. (documented) (source: 설정, 프로젝트 수준 백업)

기본값 또는 더 엄격한 제한이 계속 구성되어 있습니다.

크기가 너무 크거나 크게 증폭된 아카이브가 구성된 임계값을 넘어 허용됩니다.

단일 요청 DoS에는 보안상 중요하며, 그 외에는 가용성 버그입니다.

문서화된 사용자 구성 가능 아웃바운드 URL 표면은 기본적으로 내부 또는 비공개 대상을 거부합니다. (documented) (source: ASSET_RESTRICT_PRIVATE, PROJECT_WEB_RESTRICT_PRIVATE, WEBHOOK_RESTRICT_PRIVATE, VCS_RESTRICT_PRIVATE)

Default private-target checks are enabled and no trusted allowlist exemption applies. Direct protected HTTP requests and Git HTTPS and SSH operations retain address binding, VCS restrictions remain enabled, and VCS backends without binding use only explicitly trusted hosts. Configured per-protocol HTTP proxies remain trusted routing infrastructure.

A user-configurable screenshot URL, remote HTML URL, project website or repository browser URL, outbound webhook URL, or VCS URL reaches an internal or non-public target despite default controls.

내부 서비스 또는 메타데이터를 노출할 때 보안상 중요합니다.

Weblate records security-relevant account, permission, billing lifecycle, authenticated web-action rate-limit lockouts, and project or component setting changes in audit logs or history. Account-removal audit entries retain the former e-mail address until AUDITLOG_EXPIRY. (documented) (source: 개인정보 보호 규정 준수, 속도 제한, 결제, Weblate 2026.10)

Logging is configured, storage is available, and AUDITLOG_EXPIRY reflects the operator’s intended retention.

Missing audit trail for an action Weblate claims to log, or personal data retained beyond the configured audit-log expiry.

Security-critical when it blocks investigation of privileged changes or discloses retained personal data; privacy-impacting when data exceeds the configured retention; correctness-only for minor event gaps.

Self-service trial creation grants only the designated commercial trial plan or the Libre setup plan. (maintainer)

The deployment offers self-service hosting trials.

An authenticated user can select another public, private, or internal billing plan when creating a trial.

Security-critical when this bypasses paid service limits.

속도 제한이 적용되는 API 및 웹 작업은 구성된 속도 제한을 적용합니다. (documented) (source: Weblate의 REST API, 설정)

속도 제한이 활성화되어 있고 작동하는 데이터스토어가 뒷받침합니다.

구성된 임계값을 초과한 요청이 계속 처리됩니다.

엔드포인트 민감도에 따라 가용성/보안 강화에 해당합니다.

Built-in translation quality checks must not permit user-controlled content within configured size limits to monopolize synchronous request workers through disproportionate resource consumption. (maintainer)

The check is enabled and runs during a supported browser or API translation write.

A single accepted translation causes CPU or memory consumption disproportionate to its size and stalls a request worker.

단일 요청 DoS에는 보안상 중요하며, 그 외에는 가용성 버그입니다.

Generic webhooks schedule repository updates only for eligible components whose repository URL exactly matches a repository URL from the payload, including documented URL variants. Components managed through an authenticated integration are excluded from generic matching and diagnostics. Generic responses disclose only the documented matching diagnostics for eligible components. (documented) (source: Matching webhook targets)

Hooks are enabled and the delivery reaches an in-scope hook endpoint.

A delivery updates a component whose repository URL does not exactly match the payload, including through host or path suffix fallback, or a generic delivery updates or discloses a component managed through an authenticated integration, or a response discloses component information beyond the documented fields.

Security-critical when it causes unauthorized repository synchronization across unrelated components; otherwise correctness or hardening.

Weblate does not intentionally expose database, datastore, backup storage, or raw internal storage directly through the public web interface; exported VCS repositories are intentionally exposed by Git 내보내기 when that optional module is enabled; authorized project backup downloads are intentionally exposed through documented project backup routes. (documented) (source: Weblate의 REST API, 프로젝트 수준 백업) (maintainer)

배포는 문서화된 내보내기 기능을 제외하고 내부 스토리지 경로를 정적 파일로 제공하지 않습니다.

공개 요청이 원시 내부 스토리지, 구성 또는 내보내지 않은 저장소 데이터를 가져옵니다.

보안상 중요함.

이 모델의 리소스 임계값은 문서화된 구성 기본값이 있는 경우, 특히 백업 가져오기 제한과 속도 제한을 의미합니다. 저장소 크기, 프로젝트 수, 구성요소 수, 번역량에 대해서 Weblate는 배포 용량과 독립적인 고정된 보편적 리소스 상한을 주장하지 않습니다. (maintainer)

Component discovery is an exception: it stops after 100,000 repository paths or before performing more than 1,000,000 path-to-mask comparisons. These limits bound resource consumption when repository-controlled base files generate file masks. (maintainer)

Weblate가 제공하지 않는 보안 속성

Weblate는 지원되는 모든 포지 통합에 대해 모든 웹훅 전달을 암호학적으로 인증하지 않습니다. 훅 엔드포인트는 균일한 포지 인증보다는 호환성과 배포 강화에 초점을 둡니다. 모델링된 효과 안에 머무르는 인증되지 않은 트리거만 보여주는 보고서는 BY-DESIGN 이 아니라 VALID-HARDENING 입니다. (maintainer)

Weblate does not make an unauthenticated webhook equivalent to a trusted forge identity. Hook processing can trigger update workflows, and generic responses can confirm repository registration and reveal match counts, project/component slugs, and API URLs, including for private projects and restricted components. Components managed through an authenticated integration are excluded from this generic behavior. Attribution and authenticity are weaker than for an authenticated user or token. (maintainer)

User-requested background work is authorized when Weblate accepts and queues the request. Background tasks do not always verify the initiating user’s permissions again when they execute. Later changes to the user’s account, permissions, or team memberships therefore do not reliably prevent already-authorized work from completing. (maintainer)

Weblate는 악의적 관리자, 악의적 로컬 운영자, 서드파티 애드온, 사용자 정의 배포 코드, VCS 클라이언트 또는 백업 도구를 위한 샌드박스가 아닙니다. (maintainer)

Weblate는 번역 콘텐츠가 다운스트림 제품의 자체 이스케이프, 검증 또는 검토 없이 복사되었을 때 안전하다고 보장하지 않습니다. 번역 검사와 검토 워크플로는 현지화 품질과 위험을 관리하는 데 도움이 되지만, 완전한 다운스트림 애플리케이션 보안 경계는 아닙니다. (documented) (source: 현지화 위협 모델, 검사 및 수정)

오해하기 쉬운 지점:

  • Weblate 권한은 애플리케이션 권한 부여이지 호스트 샌드박스가 아닙니다. VCS 또는 프로젝트 관리 권한을 부여받은 사용자는 해당 역할의 권한 안에서 의도적으로 통합을 구성할 수 있습니다. (maintainer)

  • 웹훅 프로젝트 매칭과 이벤트 파싱은 통합이 전달을 인증하지 않는 경우 발신자가 합법적인 포지라는 증거가 아닙니다. (maintainer)

  • 번역 검사는 일반적인 품질 및 형식 문제를 감지합니다. 모든 다운스트림 렌더러에서 번역된 문자열이 안전하다는 보장은 아닙니다. (documented) (source: 검사 및 수정, 현지화 위협 모델)

  • BorgBackup 암호화는 Borg 설계에 따라 백업 아카이브를 보호합니다. Weblate는 Borg 내부에 대해 별도의 암호학적 보장을 추가하지 않습니다. (documented) (source: Weblate 백업 및 이전)

  • 속도 제한은 구성된 엔드포인트 남용을 줄이지만, 대규모 네트워크 공격 상황의 가용성을 보장하지는 않습니다. (maintainer)

배포 또는 다운스트림 시스템에 일부 또는 전부 맡겨지는 잘 알려진 공격 유형:

  • 피싱과 자격 증명 재사용은 인증 정책과 2FA로 완화되지만, Weblate는 사용자가 서비스 밖에서 자격 증명을 공개하는 것을 막을 수 없습니다. (maintainer)

  • 악의적 번역은 이를 안전하지 않게 렌더링하는 다운스트림 애플리케이션에서 XSS, 형식 문자열, 명령 또는 정책 문제가 될 수 있습니다. (documented) (source: 현지화 위협 모델)

  • 문서화된 비공개 대상 제한이 있는 사용자 구성 가능 아웃바운드 URL 표면은 기본적으로 내부 또는 비공개 대상을 거부합니다. 권한 있는 허용목록, 프록시, 관리자 제어 구성은 도달 가능성을 의도적으로 확장할 수 있습니다. (maintainer)

  • 큰 저장소 기록, 프로젝트 규모, 백그라운드 작업량은 Weblate의 단일 입력 검증을 넘어서는 배포 규모 산정과 운영 제한이 필요합니다. (maintainer)

다운스트림 책임

운영자는 올바른 프록시 헤더, 호스트명, 요청 크기 제한, 보안 쿠키 동작을 갖춘 프로덕션급 HTTPS 뒤에 Weblate를 배포해야 합니다. (documented) (source: 설정 지침, ENABLE_HTTPS, ALLOWED_HOSTS)

Operators enabling forwarded client-IP handling must trust only reverse proxies under their control and prevent untrusted clients from bypassing those proxies to reach Weblate directly. (documented) (source: WEBLATE_TRUSTED_PROXY_ADDRESSES, 리버스 프록시 뒤에서 실행)

운영자는 조직의 최소 권한 원칙에 따라 팀, 역할, 프로젝트 범위 토큰, VCS 자격 증명, 프로젝트 관리 권한을 할당해야 합니다. (documented) (source: 접근 제어, Weblate의 REST API)

Operators exposing 알림 후크 must enable them only where needed and provide deployment controls such as reverse-proxy rate limits, body-size limits, monitoring, and optional source restrictions. They must accept the documented identifier disclosure or use authenticated integrations where available. (maintainer)

운영자는 비공개 대상 허용목록, 프록시, 권한 있는 아웃바운드 통합 설정을 Weblate의 기본 네트워크 도달 가능성 제한을 의도적으로 확장하는 것으로 취급해야 합니다. (maintainer)

운영자는 백업 가져오기 제한, API 속도 제한, 웹 속도 제한을 인스턴스 용량과 노출에 맞는 값으로 유지해야 합니다. (documented) (source: 설정)

운영자는 Weblate 데이터 디렉터리, 구성, 백업 자격 증명, 생성된 키, 데이터베이스, 데이터스토어, 로컬 셸 접근을 신뢰된 인프라로 보호해야 합니다. (documented) (source: Weblate 백업 및 이전, 설정 지침)

다운스트림 제품 팀은 대상 렌더러에 맞게 별도로 검토, 이스케이프, 검증하지 않는 한 번역된 문자열을 자체 애플리케이션 안에서 신뢰할 수 없는 콘텐츠로 취급해야 합니다. (documented) (source: 현지화 위협 모델)

알려진 오용 패턴

  • Exposing webhook endpoints broadly, enabling project hooks, and relying on webhook payloads as authenticated forge identity. This is unsafe because some supported hooks are compatibility-oriented and return matching diagnostics. Use deployment controls and prefer authenticated integrations where available. (maintainer)

  • Granting workspace, project, VCS, or access-management permissions to users who are trusted only as translators. This is unsafe because those permissions can affect code-hosting connections, repositories, credentials, or other users. Assign narrower roles. (documented) (source: 접근 제어, Code-hosting integrations)

  • Assigning site-wide permissions to roles intended for limited project or helpdesk delegation. Site-wide permissions apply across the instance and are not narrowed by the team’s project selection. In particular, user.edit permits changing team memberships and superuser status for editable accounts, including the caller’s own account. Delegate permissions through project or workspace teams for limited scopes. (documented) (source: 접근 제어)

  • 기계 번역 제공자를 데이터 수신자로 취급하지 않고 민감한 원문 문자열이나 비공개 고객 콘텐츠를 전송하는 것. Weblate는 구성된 서비스로 콘텐츠를 전송해야 하며, 제출되는 콘텐츠는 제공자와 활성화된 기능에 따라 달라지므로 안전하지 않습니다. 프로젝트 데이터 정책에 따라 제공자를 구성하세요. (maintainer)

  • 관리 편의를 위해 신뢰할 수 없는 출처의 프로젝트 백업을 가져오는 것. 백업에는 프로젝트 메타데이터, 번역 콘텐츠, 저장소 상태가 포함되므로 안전하지 않습니다. 가져오기 제한을 활성화한 상태로 유지하고 대상 인스턴스에 적합한 백업만 가져오세요. (documented) (source: Weblate 백업 및 이전)

  • Weblate 번역 검사를 다운스트림 애플리케이션이 번역된 문자열을 통해 공격받을 수 없다는 증거로 취급하는 것. 최종 실행 컨텍스트는 다운스트림 렌더러가 정의하므로 안전하지 않습니다. 소비 애플리케이션에서 번역을 검토하고 이스케이프하세요. (documented) (source: 현지화 위협 모델)

알려진 비발견 사항

  • A report that a reachable webhook can be called without forge authentication and only triggers modeled update scheduling or returns the documented matching diagnostics is not VALID by itself. It is routed to VALID-HARDENING unless it bypasses documented limits, matches unrelated repositories, leaks data beyond the documented fields, or causes effects beyond modeled scheduling. (maintainer)

  • A report that a webhook does not update a component whose repository URL only shares a host or path suffix with the payload is not a vulnerability; Weblate matches only exact repository URLs and documented variants. (documented) (source: Matching webhook targets)

  • 프로젝트 관리자가 저장소 설정, VCS 자격 증명 또는 프로젝트 구성을 변경할 수 있다는 보고서는 행위자에게 해당 작업에 대한 문서화된 권한이 있는 경우 취약점이 아닙니다. (documented) (source: 접근 제어)

  • A report containing private-project or restricted-component data is not a vulnerability when the user has effective reports.view permission on the selected parent scope. That permission intentionally authorizes the complete report scope. (documented) (source: 번역 진행 보고, 접근 제어)

  • A report that a project manager can configure Gerrit review push options is not a vulnerability by itself. Gerrit interprets these options as the configured Weblate Gerrit account and enforces Gerrit-side permissions. (documented) (source: 푸시 브랜치)

  • 서드파티 애드온 동작에 대한 보고서는 Weblate의 권한 또는 설치 경계가 우회된다는 것을 보여주지 않는 한 Weblate 코어 취약점이 아닙니다. (maintainer)

  • 악의적 로컬 운영자가 구성을 읽거나, 관리 명령을 실행하거나, 파일을 변경할 수 있다는 보고서는 로컬 운영자가 신뢰된 인프라이므로 모델 밖입니다. (maintainer)

  • 다운스트림 애플리케이션이 위험한 번역을 렌더링한다는 보고서는 Weblate 자체가 해당 번역을 저장, 검사, 검토 또는 표시하는 동안 주장된 속성을 위반하지 않는 한 Weblate 취약점이 아닙니다. (documented) (source: 현지화 위협 모델)

이 모델을 변경하는 조건

Weblate가 새 공개 엔드포인트 계열, 새 인증 또는 토큰 모드, 새 기본 배포 모드, 새 백업 또는 가져오기 형식, 새 VCS 실행 경로, 새 아웃바운드 통합 클래스, 새 애드온 실행 기능을 추가하거나 훅, HTTPS, 속도 제한, CSP, 비공개 네트워크 접근, 백업 가져오기 제한의 기본값을 변경하면 이 모델을 개정하세요. (maintainer)

지원되지 않던 구성요소가 지원되는 제품 표면이 되거나, 문서화된 보안 속성이 제거되거나 좁아지거나, 유지관리자가 아래 분류 판정으로 라우팅할 수 없는 취약점 보고서를 수락할 때 이 모델을 개정하세요. (maintainer)

분류 판정

판정

의미

허용 근거

VALID

범위 내 행위자와 입력을 통해 Weblate가 주장하는 속성을 위반합니다.

Weblate가 제공하는 보안 속성, 입력 가정사항, 위협 모델

VALID-HARDENING

주장된 속성은 위반되지 않지만, Weblate가 모델링된 효과 안에 머무르는 호환성 웹훅 트리거 같은 알려진 오용 위험을 줄이기로 선택합니다.

알려진 오용 패턴, Weblate가 제공하지 않는 보안 속성

OUT-OF-MODEL: trusted-input

이 모델이 신뢰됨으로 표시한 입력에 대한 공격자 제어가 필요합니다.

입력 가정사항

OUT-OF-MODEL: adversary-not-in-scope

이 모델이 제외하는 능력이 필요합니다.

위협 모델

OUT-OF-MODEL: unsupported-component

서드파티 애드온, 생성된 문서, 테스트, 로컬 사용자 정의 또는 범위 밖으로 표시된 다른 구성요소에서 발생합니다.

범위 외

OUT-OF-MODEL: non-default-build

주장된 속성을 의도적으로 제거하는 배포 선택 이후에만 나타납니다.

빌드 타임 및 구성 변형

BY-DESIGN: property-disclaimed

Weblate가 명시적으로 제공하지 않는 속성과 관련됩니다.

Weblate가 제공하지 않는 보안 속성

KNOWN-NON-FINDING

문서화된 반복적 오탐과 일치합니다.

알려진 취약점 제외 항목

MODEL-GAP

위의 어떤 판정에도 깔끔하게 라우팅할 수 없습니다.

모델 변경 조건