Bug ID 1220514
Summary VUL-0: CVE-2024-1892: python-Scrapy: parts of API are vulnerable to a ReDoS attack
Classification openSUSE
Product openSUSE Distribution
Version Leap 15.6
Hardware Other
URL https://smash.suse.de/issue/395399/
OS Other
Status NEW
Severity Normal
Priority P5 - None
Component Other
Assignee dmueller@suse.com
Reporter smash_bz@suse.de
QA Contact security-team@suse.de
CC andrea.mattiazzo@suse.com
Target Milestone ---
Found By Security Response Team
Blocker ---

Parts of the Scrapy API were found to be vulnerable to a ReDoS attack. Handling
a malicious response could cause extreme CPU and memory usage during the
parsing of its content, due to the use of vulnerable regular expressions for
that parsing.

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2024-1892
https://www.cve.org/CVERecord?id=CVE-2024-1892
https://huntr.com/bounties/271f94f2-1e05-4616-ac43-41752389e26b
https://docs.scrapy.org/en/latest/news.html#scrapy-2-11-0-2023-09-18

Patch:
https://github.com/scrapy/scrapy/commit/479619b340f197a8f24c5db45bc068fb8755f2c5


You are receiving this mail because: