{"id":"CVE-2021-43857","details":"Gerapy is a distributed crawler management framework. Gerapy prior to version 0.9.8 is vulnerable to remote code execution, and this issue is patched in version 0.9.8.","aliases":["GHSA-9w7f-m4j4-j3xw","PYSEC-2021-867"],"modified":"2026-08-07T19:46:58.298199Z","published":"2021-12-27T19:15:08.683Z","references":[{"type":"ADVISORY","url":"https://github.com/Gerapy/Gerapy/security/advisories/GHSA-9w7f-m4j4-j3xw"},{"type":"REPORT","url":"https://github.com/Gerapy/Gerapy/issues/219"},{"type":"FIX","url":"https://github.com/Gerapy/Gerapy/commit/49bcb19be5e0320e7e1535f34fe00f16a3cf3b28"},{"type":"EVIDENCE","url":"http://packetstormsecurity.com/files/165459/Gerapy-0.9.7-Remote-Code-Execution.html"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/gerapy/gerapy","events":[{"introduced":"0"},{"fixed":"a821f5dc75f027f5a2c77aa40ed23f20efe85a5c"},{"fixed":"49bcb19be5e0320e7e1535f34fe00f16a3cf3b28"}],"database_specific":{"source":["CPE_RANGE","REFERENCES"],"cpe":"cpe:2.3:a:gerapy:gerapy:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"0.9.8"}]}}],"versions":["v0.9.7","v0.9.6","v0.9.6a1","v0.9.5","v0.9.4","v0.9.3","v0.9.3b1","v0.9.3a2","v0.9.3a1","v0.9.2","v0.9.2rc1","v0.9.1","v0.9.0","v0.8.8","v0.8.7","v0.8.6","v0.8.rc2","v0.8.6rc2","v0.8.5rc2","0.8.6-rc1","0.8.6-beta1","0.8.6-beta","v0.8.3","v0.8.2","v0.7.8"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-43857.json"}}],"schema_version":"1.8.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}]}