Lucene search

K
cvelist@huntrdevCVELIST:CVE-2022-0577
HistoryMar 02, 2022 - 4:05 a.m.

CVE-2022-0577 Exposure of Sensitive Information to an Unauthorized Actor in scrapy/scrapy

2022-03-0204:05:10
CWE-200
@huntrdev
www.cve.org
5
cve-2022-0577
sensitive information
unauthorized actor
github
scrapy

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

EPSS

0.002

Percentile

64.6%

Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository scrapy/scrapy prior to 2.6.1.

CNA Affected

[
  {
    "product": "scrapy/scrapy",
    "vendor": "scrapy",
    "versions": [
      {
        "lessThan": "2.6.1",
        "status": "affected",
        "version": "unspecified",
        "versionType": "custom"
      }
    ]
  }
]

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

EPSS

0.002

Percentile

64.6%