CVE-2024-31215
CVSS V2 None
CVSS V3 None
Description
Mobile Security Framework (MobSF) is a security research platform for mobile applications in Android, iOS and Windows Mobile.
A SSRF vulnerability in firebase database check logic. The attacker can cause the server to make a connection to internal-only services within the organization’s infrastructure. When a malicious app is uploaded to Static analyzer, it is possible to make internal requests. This vulnerability has been patched in version 3.9.8.
Overview
- CVE ID
- CVE-2024-31215
- Assigner
- GitHub_M
- Vulnerability Status
- PUBLISHED
- Published Version
- 2024-04-04T16:10:18.954Z
- Last Modified Date
- 2024-06-04T17:36:55.369Z
Weakness Enumerations
References
Reference URL | Reference Tags |
---|---|
https://github.com/MobSF/Mobile-Security-Framework-MobSF/security/advisories/GHSA-wpff-wm84-x5cx | x_refsource_CONFIRM |
https://github.com/MobSF/Mobile-Security-Framework-MobSF/pull/2373 | x_refsource_MISC |
https://github.com/MobSF/Mobile-Security-Framework-MobSF/commit/43bb71d115d78c03faa82d75445dd908e9b32716 | x_refsource_MISC |
Sources
Source Name | Source URL |
---|---|
NIST | https://nvd.nist.gov/vuln/detail/CVE-2024-31215 |
MITRE | https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-31215 |
History
Created | Old Value | New Value | Data Type | Notes |
---|---|---|---|---|
2024-06-25 23:01:00 | Added to TrackCVE |