Scrapy@0.22.0 vulnerabilities
A high-level Web Crawling and Web Scraping framework
-
latest version
2.11.1
-
first published
14 years ago
-
latest version published
3 months ago
-
licenses detected
- [0,)
Direct Vulnerabilities
Known vulnerabilities in the Scrapy package. This does not include vulnerabilities belonging to this package’s dependencies.
Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.Vulnerability | Vulnerable Version |
---|---|
Scrapy is a high-level web crawling and web scraping framework, used to crawl websites and extract structured data from their pages. Affected versions of this package are vulnerable to Information Exposure Through Sent Data due to the failure to remove the How to fix Information Exposure Through Sent Data? Upgrade |
[,2.11.1)
|
Scrapy is a high-level web crawling and web scraping framework, used to crawl websites and extract structured data from their pages. Affected versions of this package are vulnerable to Regular Expression Denial of Service (ReDoS) when parsing content. An attacker can cause extreme CPU and memory usage by handling a malicious response. How to fix Regular Expression Denial of Service (ReDoS)? Upgrade |
[,2.11.1)
|
Scrapy is a high-level web crawling and web scraping framework, used to crawl websites and extract structured data from their pages. Affected versions of this package are vulnerable to Improper Resource Shutdown or Release due to the enforcement of response size limits only during the download of raw, usually-compressed response bodies and not during decompression. A malicious website being scraped could send a small response that, upon decompression, could exhaust the memory available to the process, potentially affecting any other process sharing that memory, and affecting disk usage in case of uncompressed response caching. How to fix Improper Resource Shutdown or Release? Upgrade |
[,1.8.4)
[2.0.0,2.11.1)
|
Scrapy is a high-level web crawling and web scraping framework, used to crawl websites and extract structured data from their pages. Affected versions of this package are vulnerable to Regular Expression Denial of Service (ReDoS) via the Note: For versions 2.6.0 to 2.11.0, the vulnerable function is How to fix Regular Expression Denial of Service (ReDoS)? Upgrade |
[,1.8.4)
[2.0.0,2.11.1)
|
Scrapy is a high-level web crawling and web scraping framework, used to crawl websites and extract structured data from their pages. Affected versions of this package are vulnerable to Origin Validation Error due to the improper handling of the How to fix Origin Validation Error? Upgrade |
[,1.8.4)
[2.0.0,2.11.1)
|
Scrapy is a high-level web crawling and web scraping framework, used to crawl websites and extract structured data from their pages. Affected versions of this package are vulnerable to Credential Exposure via the NOTE: To fully mitigate the effects of vulnerability, replacing or upgrading the third-party downloader middleware might be necessary after upgrading. How to fix Credential Exposure? Upgrade |
[,1.8.3)
[2.0.0,2.6.2)
|
Scrapy is a high-level web crawling and web scraping framework, used to crawl websites and extract structured data from their pages. Affected versions of this package are vulnerable to Information Exposure via responses from domain names whose public domain name suffix contains 1 or more periods are able to set cookies that are included in requests to any other domain sharing the same domain name suffix. How to fix Information Exposure? Upgrade |
[,1.8.2)
[2.0.0,2.6.0)
|
Scrapy is a high-level web crawling and web scraping framework, used to crawl websites and extract structured data from their pages. Affected versions of this package are vulnerable to Information Exposure in which a spider could leak cookie headers when being forwarded to a third party, potentially attacker-controlled website. How to fix Information Exposure? Upgrade |
[,2.6.0)
|
Scrapy is a high-level web crawling and web scraping framework, used to crawl websites and extract structured data from their pages. Affected versions of this package are vulnerable to Information Exposure. If you use How to fix Information Exposure? Upgrade |
[2.0.0,2.5.1)
[,1.8.1)
|
Scrapy is a high-level web crawling and web scraping framework, used to crawl websites and extract structured data from their pages. Affected versions of this package are vulnerable to XML External Entity (XXE) Injection
via the How to fix XML External Entity (XXE) Injection? Upgrade |
[,0.24.0)
|
via |
[0,)
|