Gerapy

Gerapy

4 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.41%
  • Veröffentlicht 19.07.2026 03:00:11
  • Zuletzt bearbeitet 20.07.2026 13:30:32

A vulnerability has been found in Gerapy up to 0.9.13. The impacted element is an unknown function of the file gerapy/server/core/views.py of the component Project Upload Endpoint. Such manipulation leads to missing authentication. The attack may be ...

Exploit
  • EPSS 7.65%
  • Veröffentlicht 26.01.2022 22:15:07
  • Zuletzt bearbeitet 21.11.2024 06:07:52

Gerapy is a distributed crawler management framework. Prior to version 0.9.9, an authenticated user could execute arbitrary commands. This issue is fixed in version 0.9.9. There are no known workarounds.

Exploit
  • EPSS 55.33%
  • Veröffentlicht 27.12.2021 19:15:08
  • Zuletzt bearbeitet 21.11.2024 06:29:56

Gerapy is a distributed crawler management framework. Gerapy prior to version 0.9.8 is vulnerable to remote code execution, and this issue is patched in version 0.9.8.

  • EPSS 1.72%
  • Veröffentlicht 29.07.2020 13:15:10
  • Zuletzt bearbeitet 21.11.2024 05:37:38

This affects the package Gerapy from 0 and before 0.9.3. The input being passed to Popen, via the project_configure endpoint, isn’t being sanitized.