0.9.13
7 years ago
1 years ago
Known vulnerabilities in the gerapy package. This does not include vulnerabilities belonging to this package’s dependencies.
Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for freeVulnerability | Vulnerable Version |
---|---|
gerapy is a Distributed Crawler Management Framework Based on Scrapy, Scrapyd, Scrapyd-Client, Scrapyd-API, Django and Vue.js. Affected versions of this package are vulnerable to Arbitrary File Read. An authenticated user without permissions can send a specially crafted HTTP POST request to the server hosting ###PoC
How to fix Arbitrary File Read? Upgrade | [,0.9.9) |
gerapy is a Distributed Crawler Management Framework Based on Scrapy, Scrapyd, Scrapyd-Client, Scrapyd-API, Django and Vue.js. Affected versions of this package are vulnerable to Access Restriction Bypass. An authenticated user can execute arbitrary commands in Gerapy. PoC
How to fix Access Restriction Bypass? Upgrade | [,0.9.9) |
gerapy is a Distributed Crawler Management Framework Based on Scrapy, Scrapyd, Scrapyd-Client, Scrapyd-API, Django and Vue.js. Affected versions of this package are vulnerable to Arbitrary Code Execution via the Note: CVE-2021-44597 is a duplicate of CVE-2021-43857 How to fix Arbitrary Code Execution? Upgrade | [,0.9.8) |