CVE-2024-3572

unknown
Published 2024-02-16 · Modified 2024-04-16
CVSS v3
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS v2
VIR risk

Description

The scrapy/scrapy project is vulnerable to XML External Entity (XXE) attacks due to the use of lxml.etree.fromstring for parsing untrusted XML data without proper validation. This vulnerability allows attackers to perform denial of service attacks, access local files, generate network connections, or circumvent firewalls by submitting specially crafted XML data.

Predictions

Exploit likelihood
30%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2024-3572

OS impact

OSVersionStatusFixed in
debian debianbookwormaffected
debian debianbullseyeaffected
debian debianforkyfixed2.11.1-1
debian debiansidfixed2.11.1-1
debian debiantrixiefixed2.11.1-1

Package impact

EcosystemPackageVulnerableFixed
python PyPIscrapy>=2.0.0,<2.11.12.11.1
python PyPIscrapy<1.8.41.8.4

References

Verify integrity in audit chain (admin only). AS-IS.