← back
CVE-2021-32849highobserved exploitationCWE-78

Arbitrary command execution in Gerapy

63Vexday Risk Score

Prioritize patching. It exploitation observed by VulnCheck and has a public proof of concept.

ssvc Actcvss 8.8epss 7.6%
from disclosure to weapon89 days
Published on NVDJan 26
1st PoC+89d
VulnCheck+768d
exploitation probability
7.6%top 6% of all CVEs
observed exploitation
yesVulnCheck
1 public exploit(s)
Gerapy is a distributed crawler management framework. Prior to version 0.9.9, an authenticated user could execute arbitrary commands. This issue is fixed in version 0.9.9. There are no known workarounds.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected products
Gerapy · gerapy
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.