Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-1892

Опубликовано: 28 фев. 2024
Источник: nvd
CVSS3: 7.5
CVSS3: 6.5
EPSS Низкий

Описание

A Regular Expression Denial of Service (ReDoS) vulnerability exists in the XMLFeedSpider class of the scrapy/scrapy project, specifically in the parsing of XML content. By crafting malicious XML content that exploits inefficient regular expression complexity used in the parsing process, an attacker can cause a denial-of-service (DoS) condition. This vulnerability allows for the system to hang and consume significant resources, potentially rendering services that utilize Scrapy for XML processing unresponsive.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:scrapy:scrapy:*:*:*:*:*:*:*:*
Версия до 2.11.1 (исключая)

EPSS

Процентиль: 18%
0.00058
Низкий

7.5 High

CVSS3

6.5 Medium

CVSS3

Дефекты

CWE-1333

Связанные уязвимости

CVSS3: 6.5
ubuntu
почти 2 года назад

A Regular Expression Denial of Service (ReDoS) vulnerability exists in the XMLFeedSpider class of the scrapy/scrapy project, specifically in the parsing of XML content. By crafting malicious XML content that exploits inefficient regular expression complexity used in the parsing process, an attacker can cause a denial-of-service (DoS) condition. This vulnerability allows for the system to hang and consume significant resources, potentially rendering services that utilize Scrapy for XML processing unresponsive.

CVSS3: 6.5
debian
почти 2 года назад

A Regular Expression Denial of Service (ReDoS) vulnerability exists in ...

CVSS3: 7.5
github
почти 2 года назад

Scrapy vulnerable to ReDoS via XMLFeedSpider

EPSS

Процентиль: 18%
0.00058
Низкий

7.5 High

CVSS3

6.5 Medium

CVSS3

Дефекты

CWE-1333