Junglewise Threat Intelligence

CVE-2021-44597: PYSEC-2022-228 - An Access Control vunerabiity exists in Gerapy v 0.9.7 via the spider parameter in project_configure function.

CVE-2021-44597 · Severity: low · CVSS 3.1 · Published 2022-03-10

Technologies: gerapy (PyPI). Vendors: PyPI.

Executive brief

Gerapy is an open-source web-based framework for managing and running Scrapy web scraping projects. An authorization vulnerability in the project_configure function allows unauthenticated attackers to bypass access controls via the spider parameter, potentially enabling them to execute arbitrary code or modify project configurations.

Technical details

An access control vulnerability (CWE-863) exists in the project_configure function of Gerapy via improper authorization of the spider parameter. The vulnerability is network-accessible without requiring authentication or user interaction. Attackers can exploit this flaw to bypass authorization checks and execute arbitrary code or manipulate project configurations. The vulnerability affects all versions prior to 0.9.8. A patch is available in version 0.9.8 and later.

Affected products

  • Gerapy Gerapy before 0.9.8

Timeline

  • 2021-12-02: disclosed
  • 2022: patched: Fixed in version 0.9.8
  • 2022-03-11: advisory

References

Related threats