Executive brief
Gerapy is an open-source web-based framework for managing and running Scrapy web scraping projects. An authorization vulnerability in the project_configure function allows unauthenticated attackers to bypass access controls via the spider parameter, potentially enabling them to execute arbitrary code or modify project configurations.
Technical details
An access control vulnerability (CWE-863) exists in the project_configure function of Gerapy via improper authorization of the spider parameter. The vulnerability is network-accessible without requiring authentication or user interaction. Attackers can exploit this flaw to bypass authorization checks and execute arbitrary code or manipulate project configurations. The vulnerability affects all versions prior to 0.9.8. A patch is available in version 0.9.8 and later.
Affected products
- Gerapy Gerapy before 0.9.8
Timeline
- 2021-12-02: disclosed
- 2022: patched: Fixed in version 0.9.8
- 2022-03-11: advisory