4.4.2
4 years ago
19 days ago
Known vulnerabilities in the mobsf package. This does not include vulnerabilities belonging to this package’s dependencies.
Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for freeVulnerability | Vulnerable Version |
---|---|
mobsf is a Mobile Security Framework (MobSF) is an automated, all-in-one mobile application (Android/iOS/Windows) pen-testing, malware analysis and security assessment framework capable of performing static and dynamic analysis. Affected versions of this package are vulnerable to Directory Traversal via the How to fix Directory Traversal? Upgrade | [4.4.0,4.4.2) |
mobsf is a Mobile Security Framework (MobSF) is an automated, all-in-one mobile application (Android/iOS/Windows) pen-testing, malware analysis and security assessment framework capable of performing static and dynamic analysis. Affected versions of this package are vulnerable to Improper Handling of Highly Compressed Data (Data Amplification) through the ZIP file upload functionality. An attacker can exhaust the server's disk space, leading to a complete denial of service for MobSF and potentially other applications or websites hosted on the same server by crafting a specially prepared ZIP file that expands significantly upon extraction. How to fix Improper Handling of Highly Compressed Data (Data Amplification)? Upgrade | [0,4.4.2) |
mobsf is a Mobile Security Framework (MobSF) is an automated, all-in-one mobile application (Android/iOS/Windows) pen-testing, malware analysis and security assessment framework capable of performing static and dynamic analysis. Affected versions of this package are vulnerable to Cross-site Scripting (XSS) due to improper sanitization of user-supplied SVG files during the Android APK analysis workflow. An attacker can execute arbitrary scripts in the context of the MobSF user session by uploading a malicious SVG file as an app icon and accessing the publicly available URL. How to fix Cross-site Scripting (XSS)? Upgrade | [0,4.4.2) |
mobsf is a Mobile Security Framework (MobSF) is an automated, all-in-one mobile application (Android/iOS/Windows) pen-testing, malware analysis and security assessment framework capable of performing static and dynamic analysis. Affected versions of this package are vulnerable to Insecure Permissions due to missing access restrictions. An attacker can append How to fix Insecure Permissions? There is no fixed version for | [0,) |