GHSA-9w7f-m4j4-j3xw
Dashboard / Vulnerabilities / GHSA-9w7f-m4j4-j3xw
GHSA-9w7f-m4j4-j3xw
Summary: Gerapy may cause remote code execution
Details: ### Impact project_configure function exist remote code execute in Gerapy < 0.9.8 ### Patches Patched in version 0.9.8, please install with: ``` pip3 install -U gerapy ```
References: https://github.com/Gerapy/Gerapy/security/advisories/GHSA-9w7f-m4j4-j3xw, https://nvd.nist.gov/vuln/detail/CVE-2021-43857, https://github.com/Gerapy/Gerapy/issues/219, https://github.com/Gerapy/Gerapy/commit/49bcb19be5e0320e7e1535f34fe00f16a3cf3b28, https://github.com/Gerapy/Gerapy, https://github.com/pypa/advisory-database/tree/main/vulns/gerapy/PYSEC-2021-867.yaml, https://github.com/pypa/advisory-database/tree/main/vulns/gerapy/PYSEC-2022-228.yaml, http://packetstormsecurity.com/files/165459/Gerapy-0.9.7-Remote-Code-Execution.html
Affected packages
Package
Name: gerapy
Purl: pkg:pypi/gerapy
Affected ranges
Type: ECOSYSTEM
Events:
