cve/2024/CVE-2024-31215.md
2024-05-25 21:48:12 +02:00

18 lines
1011 B
Markdown
Raw Blame History

This file contains ambiguous Unicode characters

This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

### [CVE-2024-31215](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-31215)
![](https://img.shields.io/static/v1?label=Product&message=Mobile-Security-Framework-MobSF&color=blue)
![](https://img.shields.io/static/v1?label=Version&message=%3D%20%3C%3D%203.9.7%20&color=brighgreen)
![](https://img.shields.io/static/v1?label=Vulnerability&message=CWE-918%3A%20Server-Side%20Request%20Forgery%20(SSRF)&color=brighgreen)
### Description
Mobile Security Framework (MobSF) is a security research platform for mobile applications in Android, iOS and Windows Mobile.A SSRF vulnerability in firebase database check logic. The attacker can cause the server to make a connection to internal-only services within the organizations infrastructure. When a malicious app is uploaded to Static analyzer, it is possible to make internal requests. This vulnerability has been patched in version 3.9.8.
### POC
#### Reference
No PoCs from references.
#### Github
- https://github.com/fkie-cad/nvd-json-data-feeds