PT-2017-17597 · Cloudflare · Cloudflare-Scrape

Franciscouzo

·

Publicado

2017-03-23

·

Atualizado

2019-10-03

·

CVE-2017-7235

CVSS v3.1

8.8

Alta

VetorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions cloudflare-scrape versions 1.6.6 through 1.7.1
Description A malicious website owner could craft a page that executes arbitrary Python code against any cfscrape user who scrapes that website.
Recommendations For versions 1.6.6 through 1.7.1, update to version 1.8.0 to resolve the issue.

Correção

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2017-7235
GHSA-5MC5-5J6C-QMF9
PYSEC-2017-7

Produtos afetados

Cloudflare-Scrape