CVE-2021-41125
Summary
| CVE | CVE-2021-41125 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-10-06 18:15:00 UTC |
| Updated | 2022-04-22 16:00:00 UTC |
| Description | Scrapy is a high-level web crawling and scraping framework for Python. If you use `HttpAuthMiddleware` (i.e. the `http_user` and `http_pass` spider attributes) for HTTP authentication, all requests will expose your credentials to the request target. This includes requests generated by Scrapy components, such as `robots.txt` requests sent by Scrapy when the `ROBOTSTXT_OBEY` setting is set to `True`, or as requests reached through redirects. Upgrade to Scrapy 2.5.1 and use the new `http_auth_domain` spider attribute to control which domains are allowed to receive the configured HTTP authentication credentials. If you are using Scrapy 1.8 or a lower version, and upgrading to Scrapy 2.5.1 is not an option, you may upgrade to Scrapy 1.8.1 instead. If you cannot upgrade, set your HTTP authentication credentials on a per-request basis, using for example the `w3lib.http.basic_auth_header` function to convert your credentials into a value that you can assign to the `Authorization` header of your request, instead of defining your credentials globally using `HttpAuthMiddleware`. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| w3lib Package — w3lib 1.22.0 documentation |
MISC |
w3lib.readthedocs.io |
|
| HTTP authentication credentials potentially leaked to target websites · Advisory · scrapy/scrapy · GitHub |
CONFIRM |
github.com |
|
| [SECURITY] [DLA 2950-1] python-scrapy security update |
MLIST |
lists.debian.org |
|
| Downloader Middleware — Scrapy 2.5.1 documentation |
MISC |
doc.scrapy.org |
|
| Add http_auth_domain to HttpAuthMiddleware. · scrapy/scrapy@b01d69a · GitHub |
MISC |
github.com |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 179129 Debian Security Update for python-scrapy (DLA 2950-1)
- 180859 Debian Security Update for python-scrapy (CVE-2021-41125)
- 980491 Python (pip) Security Update for Scrapy (GHSA-jwqp-28gf-p498)