CVE-2024-54000

CVSS V2 None CVSS V3 None
Description
Mobile Security Framework (MobSF) is a pen-testing, malware analysis and security assessment framework capable of performing static and dynamic analysis. In versions prior to 3.9.7, the requests.get() request in the _check_url method is specified as allow_redirects=True, which allows a server-side request forgery when a request to .well-known/assetlinks.json" returns a 302 redirect. This is a bypass of the fix for CVE-2024-29190 and is fixed in 3.9.7.
Overview
  • CVE ID
  • CVE-2024-54000
  • Assigner
  • GitHub_M
  • Vulnerability Status
  • PUBLISHED
  • Published Version
  • 2024-12-03T15:33:56.232Z
  • Last Modified Date
  • 2024-12-03T17:01:38.678Z
History
Created Old Value New Value Data Type Notes
2024-12-04 13:09:30 Added to TrackCVE