CVE-2024-54000 : MOBSF MOBILE-SECURITY-FRAMEWORK- UP TO 3.9.6 302 REDIRECT SERVER-SIDE REQUEST FORGERY

Description

Mobile Security Framework (MobSF) is a pen-testing, malware analysis and security assessment framework capable of performing static and dynamic analysis. In versions prior to 3.9.7, the requests.get() request in the _check_url method is specified as allow_redirects=True, which allows a server-side request forgery when a request to .well-known/assetlinks.json” returns a 302 redirect. This is a bypass of the fix for CVE-2024-29190 and is fixed in 3.9.7.

References

https://github.com/MobSF/Mobile-Security-Framework-MobSF/security/advisories/GHSA-m435-9v6r-v5f6

https://github.com/MobSF/Mobile-Security-Framework-MobSF/commit/f22c584aa7d43527970c9da61eb678953cfc0a8e

For More Information

CVERecord

Common Vulnerabilityies and Exposures

Contact us to get started

CVE-2024-51771 : HPE ARUBA NETWORKING CLEARPASS POLICY MANAGER UP TO 6.11.9/6.12.2 WEB-BASED MANAGEMENT INTERFACE OS COMMAND INJECTION

CVE-2024-51771 : HPE ARUBA NETWORKING CLEARPASS POLICY MANAGER UP TO 6.11.9/6.12.2 WEB-BASED MANAGEMENT INTERFACE OS COMMAND INJECTION

Description A vulnerability in the HPE Aruba Networking ClearPass Policy Manager web-based management interface could allow an authenticated remote threat

CVE-2024-54000 : MOBSF MOBILE-SECURITY-FRAMEWORK- UP TO 3.9.6 302 REDIRECT SERVER-SIDE REQUEST FORGERY

CVE-2024-54000 : MOBSF MOBILE-SECURITY-FRAMEWORK- UP TO 3.9.6 302 REDIRECT SERVER-SIDE REQUEST FORGERY

Description Mobile Security Framework (MobSF) is a pen-testing, malware analysis and security assessment framework capable of performing static and dynamic

CVE-2024-40691 : IBM COGNOS CONTROLLER 11.0.0/11.0.1 WEB INTERFACE UNRESTRICTED UPLOAD

CVE-2024-40691 : IBM COGNOS CONTROLLER 11.0.0/11.0.1 WEB INTERFACE UNRESTRICTED UPLOAD

Description IBM Cognos Controller 11.0.0 and 11.0.1 could be vulnerable to malicious file upload by not validating the content of