PYSEC-2017-7

See a problem?
Import Source
https://github.com/pypa/advisory-database/blob/main/vulns/cfscrape/PYSEC-2017-7.yaml
JSON Data
https://api.osv.dev/v1/vulns/PYSEC-2017-7
Aliases
Published
2017-03-23T04:59:00Z
Modified
2023-11-08T03:59:24.135930Z
Summary
[none]
Details

An issue was discovered in cloudflare-scrape 1.6.6 through 1.7.1. A malicious website owner could craft a page that executes arbitrary Python code against any cfscrape user who scrapes that website. This is fixed in 1.8.0.

References

Affected packages

PyPI / cfscrape

Package

Affected ranges

Type
ECOSYSTEM
Events
Introduced
1.6.6
Fixed
1.8.0

Affected versions

1.*

1.6.6
1.6.7
1.6.8
1.7.0
1.7.1