Логотип exploitDog
bind:CVE-2024-3572
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-3572

Количество 4

Количество 4

ubuntu логотип

CVE-2024-3572

почти 2 года назад

The scrapy/scrapy project is vulnerable to XML External Entity (XXE) attacks due to the use of lxml.etree.fromstring for parsing untrusted XML data without proper validation. This vulnerability allows attackers to perform denial of service attacks, access local files, generate network connections, or circumvent firewalls by submitting specially crafted XML data.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2024-3572

почти 2 года назад

The scrapy/scrapy project is vulnerable to XML External Entity (XXE) attacks due to the use of lxml.etree.fromstring for parsing untrusted XML data without proper validation. This vulnerability allows attackers to perform denial of service attacks, access local files, generate network connections, or circumvent firewalls by submitting specially crafted XML data.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2024-3572

почти 2 года назад

The scrapy/scrapy project is vulnerable to XML External Entity (XXE) a ...

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-7j7m-v7m3-jqm7

почти 2 года назад

Scrapy decompression bomb vulnerability

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2024-3572

The scrapy/scrapy project is vulnerable to XML External Entity (XXE) attacks due to the use of lxml.etree.fromstring for parsing untrusted XML data without proper validation. This vulnerability allows attackers to perform denial of service attacks, access local files, generate network connections, or circumvent firewalls by submitting specially crafted XML data.

CVSS3: 7.5
0%
Низкий
почти 2 года назад
nvd логотип
CVE-2024-3572

The scrapy/scrapy project is vulnerable to XML External Entity (XXE) attacks due to the use of lxml.etree.fromstring for parsing untrusted XML data without proper validation. This vulnerability allows attackers to perform denial of service attacks, access local files, generate network connections, or circumvent firewalls by submitting specially crafted XML data.

CVSS3: 7.5
0%
Низкий
почти 2 года назад
debian логотип
CVE-2024-3572

The scrapy/scrapy project is vulnerable to XML External Entity (XXE) a ...

CVSS3: 7.5
0%
Низкий
почти 2 года назад
github логотип
GHSA-7j7m-v7m3-jqm7

Scrapy decompression bomb vulnerability

CVSS3: 7.5
0%
Низкий
почти 2 года назад

Уязвимостей на страницу