CVE-2021-43857: Gerapy may contain remote code execution vulnerability
Impact
projectconfigure function exist remote code execute in Gerapy < 0.9.8
Patches
Patched in version 0.9.8, please install with:
pip3 install -U gerapy
Other sources
Gerapy is a distributed crawler management framework. Gerapy prior to version 0.9.8 is vulnerable to remote code execution, and this issue is patched in version 0.9.8.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2021-43857.
What is the title of the vulnerability?
The title of the vulnerability is "Gerapy is a distributed crawler management framework. Gerapy prior to version 0.9.8 is vulnerable to...".
What is the impact of the vulnerability?
The impact of the vulnerability is remote code execution in Gerapy versions prior to 0.9.8.
What is the severity of the vulnerability?
The severity of the vulnerability is critical with a CVSS score of 9.8.
How can I patch the vulnerability?
You can patch the vulnerability by installing version 0.9.8 of Gerapy using the command: 'pip3 install -U gerapy'.