Mobile Security Framework (MobSF) is a pen-testing, malware analysis and security assessment framework capable of performing static and dynamic analysis. Before 4.0.7, there is a flaw in the Static Libraries analysis section. Specifically, during the extraction of .a extension files, the measure intended to prevent Zip Slip attacks is improperly implemented. Since the implemented measure can be bypassed, the vulnerability allows an attacker to extract files to any desired location within the server running MobSF. This vulnerability is fixed in 4.0.7.
History

Tue, 20 Aug 2024 16:45:00 +0000

Type Values Removed Values Added
First Time appeared Opensecurity
Opensecurity mobile Security Framework
Weaknesses CWE-22
CPEs cpe:2.3:a:opensecurity:mobile_security_framework:*:*:*:*:*:*:*:*
Vendors & Products Opensecurity
Opensecurity mobile Security Framework

Mon, 19 Aug 2024 16:30:00 +0000

Type Values Removed Values Added
First Time appeared Mobsf
Mobsf mobile Security Framework
CPEs cpe:2.3:a:mobsf:mobile_security_framework:*:*:*:*:*:*:*:*
Vendors & Products Mobsf
Mobsf mobile Security Framework
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 19 Aug 2024 15:00:00 +0000

Type Values Removed Values Added
Description Mobile Security Framework (MobSF) is a pen-testing, malware analysis and security assessment framework capable of performing static and dynamic analysis. Before 4.0.7, there is a flaw in the Static Libraries analysis section. Specifically, during the extraction of .a extension files, the measure intended to prevent Zip Slip attacks is improperly implemented. Since the implemented measure can be bypassed, the vulnerability allows an attacker to extract files to any desired location within the server running MobSF. This vulnerability is fixed in 4.0.7.
Title Mobile Security Framework (MobSF) has a Zip Slip Vulnerability in .a Static Library Files
Weaknesses CWE-23
References
Metrics cvssV3_1

{'score': 8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2024-08-19T14:44:47.180Z

Updated: 2024-08-19T15:27:04.688Z

Reserved: 2024-08-12T18:02:04.965Z

Link: CVE-2024-43399

cve-icon Vulnrichment

Updated: 2024-08-19T15:26:34.509Z

cve-icon NVD

Status : Analyzed

Published: 2024-08-19T15:15:09.073

Modified: 2024-08-20T16:21:22.747

Link: CVE-2024-43399

cve-icon Redhat

No data.