Safety vulnerability ID: 38636
The information on this page was manually curated by our Cybersecurity Intelligence Team.
This affects the package Gerapy from 0 and before 0.9.3. The input being passed to Popen, via the project_configure endpoint, isn’t being sanitized. See: CVE-2020-7698.
Latest version: 0.9.13
Distributed Crawler Management Framework Based on Scrapy, Scrapyd, Scrapyd-Client, Scrapyd-API, Django and Vue.js.
This affects the package Gerapy from 0 and before 0.9.3. The input being passed to Popen, via the project_configure endpoint, isn’t being sanitized.
MISC:https://github.com/Gerapy/Gerapy/commit/e8446605eb2424717418eae199ec7aad573da2d2: https://github.com/Gerapy/Gerapy/commit/e8446605eb2424717418eae199ec7aad573da2d2
MISC:https://snyk.io/vuln/SNYK-PYTHON-GERAPY-572470: https://snyk.io/vuln/SNYK-PYTHON-GERAPY-572470
Scan your Python project for dependency vulnerabilities in two minutes
Scan your application