—
PYSEC-2021-867
Quick fix
PYSEC-2021-867 — gerapy: upgrade to the fixed version with the command below.
pip install --upgrade 'gerapy>=49bcb19be5e0320e7e1535f34fe00f16a3cf3b28'Details
Gerapy is a distributed crawler management framework. Gerapy prior to version 0.9.8 is vulnerable to remote code execution, and this issue is patched in version 0.9.8.
Are you affected?
Enter the version of the package you're using.
Affected packages
PyPI/gerapy
Introduced in:
0Fixed in: 49bcb19be5e0320e7e1535f34fe00f16a3cf3b28Fix
pip install --upgrade 'gerapy>=49bcb19be5e0320e7e1535f34fe00f16a3cf3b28'References
- https://github.com/Gerapy/Gerapy/security/advisories/GHSA-9w7f-m4j4-j3xw[ADVISORY]
- https://github.com/Gerapy/Gerapy/issues/219[REPORT]
- https://github.com/Gerapy/Gerapy/commit/49bcb19be5e0320e7e1535f34fe00f16a3cf3b28[FIX]
- http://packetstormsecurity.com/files/165459/Gerapy-0.9.7-Remote-Code-Execution.html[WEB]