← back
CVE-2021-43857

Gerapy may contain remote code execution vulnerability

CVSS 9.8 CRITICALEPSS 55.6%CWE-78
Vexday Risk Score
60Attention
SSVC decision (CISA)
Attend
PoC available → attend closely
CVSS 9.8EPSS 55.6%KEV nãoPoC públicaNuclei Metasploit Patch
Lifecycle
27 Dec 2021Published on NVD
05 Jan 2022Public PoC
Recommendation: Plan a near-term fix — a public PoC already exists.
Gerapy is a distributed crawler management framework. Gerapy prior to version 0.9.8 is vulnerable to remote code execution, and this issue is patched in version 0.9.8.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
Gerapy · Gerapy
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →