PT-2017-17597 · Cloudflare · Cloudflare-Scrape
Franciscouzo
·
Published
2017-03-23
·
Updated
2019-10-03
·
CVE-2017-7235
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
cloudflare-scrape versions 1.6.6 through 1.7.1
Description
A malicious website owner could craft a page that executes arbitrary Python code against any cfscrape user who scrapes that website.
Recommendations
For versions 1.6.6 through 1.7.1, update to version 1.8.0 to resolve the issue.
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cloudflare-Scrape