Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2024-3572

Опубликовано: 16 апр. 2024
Источник: debian
EPSS Низкий

Описание

The scrapy/scrapy project is vulnerable to XML External Entity (XXE) attacks due to the use of lxml.etree.fromstring for parsing untrusted XML data without proper validation. This vulnerability allows attackers to perform denial of service attacks, access local files, generate network connections, or circumvent firewalls by submitting specially crafted XML data.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
python-scrapyfixed2.11.1-1package
python-scrapyno-dsabookwormpackage
python-scrapyno-dsabullseyepackage
python-scrapypostponedbusterpackage

Примечания

  • https://huntr.com/bounties/c4a0fac9-0c5a-4718-9ee4-2d06d58adabb

  • https://github.com/scrapy/scrapy/commit/809bfac4890f75fc73607318a04d2ccba71b3d9f (2.11.1)

  • The CVE and bounty descriptions discuss general XML issues (not specifically XXE), but

  • the bounty comments and the patch discuss a compression bomb.

  • https://github.com/scrapy/scrapy/security/advisories/GHSA-7j7m-v7m3-jqm7 (compression bomb)

EPSS

Процентиль: 37%
0.00157
Низкий

Связанные уязвимости

CVSS3: 7.5
ubuntu
почти 2 года назад

The scrapy/scrapy project is vulnerable to XML External Entity (XXE) attacks due to the use of lxml.etree.fromstring for parsing untrusted XML data without proper validation. This vulnerability allows attackers to perform denial of service attacks, access local files, generate network connections, or circumvent firewalls by submitting specially crafted XML data.

CVSS3: 7.5
nvd
почти 2 года назад

The scrapy/scrapy project is vulnerable to XML External Entity (XXE) attacks due to the use of lxml.etree.fromstring for parsing untrusted XML data without proper validation. This vulnerability allows attackers to perform denial of service attacks, access local files, generate network connections, or circumvent firewalls by submitting specially crafted XML data.

CVSS3: 7.5
github
почти 2 года назад

Scrapy decompression bomb vulnerability

EPSS

Процентиль: 37%
0.00157
Низкий