URL Redirection to Untrusted Site ('Open Redirect') Affecting mobsf package, versions [0,]


Severity

Recommended
0.0
medium
0
10

CVSS assessment made by Snyk's Security Team. Learn more

Threat Intelligence

Exploit Maturity
Proof of concept
EPSS
0.07% (34th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about URL Redirection to Untrusted Site ('Open Redirect') vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-PYTHON-MOBSF-7577226
  • published1 Aug 2024
  • disclosed31 Jul 2024
  • creditMarcin Węgłowski

Introduced: 31 Jul 2024

CVE-2024-41955  (opens in a new tab)
CWE-601  (opens in a new tab)

How to fix?

A fix was pushed into the master branch but not yet published.

Overview

mobsf is a Mobile Security Framework (MobSF) is an automated, all-in-one mobile application (Android/iOS/Windows) pen-testing, malware analysis and security assessment framework capable of performing static and dynamic analysis.

Affected versions of this package are vulnerable to URL Redirection to Untrusted Site ('Open Redirect') through the authentication view by manipulating the redirect URL after a successful login.

Note:* This is only exploitable if the authentication feature is enabled.

Workaround

Users that are unable to upgrade to the fixed version can disable the authentication feature

CVSS Scores

version 4.0
version 3.1