VDB
CVE-2024-1892
CVE-2024-1892
PUBLISHED
CVSS 7.5 HIGH
Scrapy vulnerable to ReDoS via XMLFeedSpider
EPSS 0.06% · 18.5th percentile
Risk Scores
CVSS 3.0
7.5
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS Score
0.06%
18.5th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| scrapy | scrapy/scrapy | unspecified, unspecified |
| scrapy | scrapy | 0, 0 |
| PyPI | scrapy | 2, 0, 2 |
| scrapy | scrapy | 0, 0 |
Exploit Intelligence
- CIRCL seen: CVE-2024-1892 (circl-sighting)
- CIRCL seen: CVE-2024-1892 (circl-sighting)
- https://huntr.com/bounties/271f94f2-1e05-4616-ac43-41752389e26b (nist-nvd)
- https://github.com/scrapy/scrapy/commit/479619b340f197a8f24c5db45bc068fb8755f2c5 (circl)
Timeline
- Feb 15, 2024 CVE Published
- Feb 28, 2024 EPSS Score
- Feb 28, 2024 PoC Published
- Feb 28, 2024 PoC Published
- Mar 25, 2024 EPSS Score
- Apr 21, 2024 EPSS Score
- May 17, 2024 EPSS Score
- Jun 13, 2024 EPSS Score
- Jul 9, 2024 EPSS Score
- Aug 9, 2024 EPSS Score
- Sep 4, 2024 EPSS Score
- Oct 1, 2024 EPSS Score
References
- https://huntr.com/bounties/271f94f2-1e05-4616-ac43-41752389e26b url
- https://github.com/scrapy/scrapy/commit/479619b340f197a8f24c5db45bc068fb8755f2c5 url
- https://github.com/scrapy/scrapy/security/advisories/GHSA-cc65-xxvf-f7r9 url
- https://github.com/scrapy/scrapy/commit/73e7c0ed011a0565a1584b8052ec757b54e5270b url
- https://docs.scrapy.org/en/latest/news.html#scrapy-1-8-4-2024-02-14 url
- https://docs.scrapy.org/en/latest/news.html#scrapy-2-11-1-2024-02-14 url
- https://github.com/pypa/advisory-database/tree/main/vulns/scrapy/PYSEC-2024-162.yaml url
- https://github.com/scrapy/scrapy package