Path to this page:
Subject: CVS commit: pkgsrc/www/py-cfscrape
From: Adam Ciarcinski
Date: 2017-07-28 09:04:36
Message id: 20170728070436.988A1FACD@cvs.NetBSD.org
Log Message:
1.8.0:
Remove insecure Js2Py library (code execution risk)
Please upgrade to 1.8.0 immediately.
Versions 1.6.6 to 1.7.1 are vulnerable to code execution. If you are running a \
vulnerable version, a malicious website owner could craft a page which executes \
arbitrary Python code on the machine that runs this script. This can only occur \
if the website that the user attempts to scrape has specifically prepared a page \
to exploit vulnerable versions of cfscrape.
Files: