CVE-2024-3572
HIGHDescription
The scrapy/scrapy project is vulnerable to XML External Entity (XXE) attacks due to the use of lxml.etree.fromstring for parsing untrusted XML data without proper validation. This vulnerability allows attackers to perform denial of service attacks, access local files, generate network connections, or circumvent firewalls by submitting specially crafted XML data.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| scrapy | scrapy |
References
Advisories & Patches
Frequently Asked Questions
What is CVE-2024-3572? +
How severe is CVE-2024-3572? +
What products are affected by CVE-2024-3572? +
How do I check if I'm vulnerable to CVE-2024-3572? +
Related Vulnerabilities
pypdf is a free and open-source pure-python PDF library. Prior to version 6.4.0, an attacker who uses this vulnerability can …
Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in ninenines cowlib allows unauthenticated remote denial of service via memory …
pypdf is a free and open-source pure-python PDF library. Prior to version 6.1.3, an attacker who uses this vulnerability can …
Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. In …
.NET and Visual Studio Denial of Service Vulnerability
urllib3 is a user-friendly HTTP client library for Python. Starting in version 1.0 and prior to 2.6.0, the Streaming API …