← Back

Gerapy

gerapy

3 CVEs • 1 product

Products (1)

Click to collapse
Toggle
Gerapy
gerapy

CVEs (3)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Gerapy
1Gerapy
Nov 21, 2024
Jan 26, 2022
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
Gerapy is a distributed crawler management framework. Prior to version 0.9.9, an authenticated user could execute arbitrary commands. This issue is fixed in version 0.9.9. There are no known workarounds.
1Gerapy
1Gerapy
Nov 21, 2024
Dec 27, 2021
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Gerapy is a distributed crawler management framework. Gerapy prior to version 0.9.8 is vulnerable to remote code execution, and this issue is patched in version 0.9.8.
1Gerapy
1Gerapy
Nov 21, 2024
Jul 29, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
This affects the package Gerapy from 0 and before 0.9.3. The input being passed to Popen, via the project_configure endpoint, isn’t being sanitized.