Scrapy 是一个面向 Python 的高级网络爬虫和网页数据采集框架。在版本 1.4.0 至 2.14.2 之间,Scrapy 的 (位于 )存在安全漏洞:当解析 HTTP 响应头中的 字段时,如果其值类似于 Python 模块导入路径(例如类似 的格式),该中间件会将其视为一个引用策略类的名称,进而动态导入该对象并调用它。 攻击者可通过构造恶意的 HTTP 响应头,注入可调用对象(如 ),从而导致正在处理该响应的爬虫进程被终止,引发拒绝服务(DoS)攻击。 该问题已在 Scrapy 2.14.2 版本中修复。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet