PT-2022-12183 · Gerapy · Gerapy

Published

2022-03-10

·

Updated

2022-10-31

·

CVE-2021-44597

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Gerapy version 0.9.7
Description An Access Control issue exists in Gerapy via the spider parameter in the project configure function.
Recommendations For Gerapy version 0.9.7, consider restricting access to the project configure function until a patch is available. As a temporary workaround, avoid using the spider parameter in the affected function to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this issue.

Fix

Incorrect Authorization

Weakness Enumeration

Related Identifiers

CVE-2021-44597
GHSA-29VR-79W7-P649
PYSEC-2022-228

Affected Products

Gerapy