PT-2017-17597 · Cloudflare · Cloudflare-Scrape
Franciscouzo
·
Publicado
2017-03-23
·
Atualizado
2019-10-03
·
CVE-2017-7235
CVSS v3.1
8.8
Alta
| Vetor | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
cloudflare-scrape versions 1.6.6 through 1.7.1
Description
A malicious website owner could craft a page that executes arbitrary Python code against any cfscrape user who scrapes that website.
Recommendations
For versions 1.6.6 through 1.7.1, update to version 1.8.0 to resolve the issue.
Correção
RCE
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Cloudflare-Scrape