{"id":"UBUNTU-CVE-2021-41125","details":"Scrapy is a high-level web crawling and scraping framework for Python. If you use `HttpAuthMiddleware` (i.e. the `http_user` and `http_pass` spider attributes) for HTTP authentication, all requests will expose your credentials to the request target. This includes requests generated by Scrapy components, such as `robots.txt` requests sent by Scrapy when the `ROBOTSTXT_OBEY` setting is set to `True`, or as requests reached through redirects. Upgrade to Scrapy 2.5.1 and use the new `http_auth_domain` spider attribute to control which domains are allowed to receive the configured HTTP authentication credentials. If you are using Scrapy 1.8 or a lower version, and upgrading to Scrapy 2.5.1 is not an option, you may upgrade to Scrapy 1.8.1 instead. If you cannot upgrade, set your HTTP authentication credentials on a per-request basis, using for example the `w3lib.http.basic_auth_header` function to convert your credentials into a value that you can assign to the `Authorization` header of your request, instead of defining your credentials globally using `HttpAuthMiddleware`.","modified":"2026-01-30T01:03:44.796523Z","published":"2021-10-06T18:15:00Z","related":["USN-7476-1"],"upstream":["CVE-2021-41125"],"references":[{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2021-41125"},{"type":"REPORT","url":"https://github.com/scrapy/scrapy/security/advisories/GHSA-jwqp-28gf-p498"},{"type":"REPORT","url":"https://github.com/scrapy/scrapy/commit/b01d69a1bf48060daec8f751368622352d8b85a6"},{"type":"REPORT","url":"https://w3lib.readthedocs.io/en/latest/w3lib.html#w3lib.http.basic_auth_header"},{"type":"REPORT","url":"http://doc.scrapy.org/en/latest/topics/downloader-middleware.html#module-scrapy.downloadermiddlewares.httpauth"},{"type":"REPORT","url":"https://www.cve.org/CVERecord?id=CVE-2021-41125"},{"type":"ADVISORY","url":"https://ubuntu.com/security/notices/USN-7476-1"}],"affected":[{"package":{"name":"python-scrapy","ecosystem":"Ubuntu:16.04:LTS","purl":"pkg:deb/ubuntu/python-scrapy@1.0.3-1?arch=source&distro=xenial"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1.0.0-1","1.0.3-1"],"ecosystem_specific":{"binaries":[{"binary_name":"python-scrapy","binary_version":"1.0.3-1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2021/UBUNTU-CVE-2021-41125.json"}},{"package":{"name":"python-scrapy","ecosystem":"Ubuntu:Pro:18.04:LTS","purl":"pkg:deb/ubuntu/python-scrapy@1.5.0-1ubuntu0.1~esm1?arch=source&distro=esm-apps/bionic"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.5.0-1ubuntu0.1~esm1"}]}],"versions":["1.3.0-1~exp2","1.4.0-1","1.5.0-1"],"ecosystem_specific":{"availability":"Available with Ubuntu Pro: https://ubuntu.com/pro","binaries":[{"binary_name":"python-scrapy","binary_version":"1.5.0-1ubuntu0.1~esm1"},{"binary_name":"python3-scrapy","binary_version":"1.5.0-1ubuntu0.1~esm1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2021/UBUNTU-CVE-2021-41125.json"}},{"package":{"name":"python-scrapy","ecosystem":"Ubuntu:Pro:20.04:LTS","purl":"pkg:deb/ubuntu/python-scrapy@1.7.3-1ubuntu0.1~esm1?arch=source&distro=esm-apps/focal"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.7.3-1ubuntu0.1~esm1"}]}],"versions":["1.7.3-1"],"ecosystem_specific":{"availability":"Available with Ubuntu Pro: https://ubuntu.com/pro","binaries":[{"binary_version":"1.7.3-1ubuntu0.1~esm1","binary_name":"python3-scrapy"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2021/UBUNTU-CVE-2021-41125.json"}}],"schema_version":"1.7.3","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"},{"type":"Ubuntu","score":"medium"}]}