CVE-2021-32849 is a critical vulnerability affecting Gerapy, a distributed crawler management framework, prior to version 0.9.9. This flaw allows an authenticated user to execute arbitrary commands, posing a significant risk to system integrity and data confidentiality. With a CVSS score of 8.8 (HIGH), the vulnerability is easily exploitable over the network with low privileges and no user interaction, leading to complete compromise of confidentiality, integrity, and availability. While no active exploitation or public exploit code is currently known, and community discussion is minimal, its high EPSS and FAUCET Risk Score indicate a substantial potential for future exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 0.9.9CPE matchmatch criteria | cpe:2.3:a:gerapy:gerapy:*:*:*:*:*:*:*:* | ||
>= 0.9.9, < 0.9.9CPE match | cpe:2.3:a:gerapy:gerapy:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.