Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-8434-v7xw-8m9x

Опубликовано: 21 янв. 2022
Источник: github
Github: Прошло ревью
CVSS3: 9.3

Описание

Improper Neutralization of Argument Delimiters in a Decompiling Package Process in APKLeaks

APKLeaks prior to v2.0.4 allows remote authenticated attackers to execute arbitrary OS commands via package name inside the application manifest.

Impact

An authenticated attacker could include arguments that allow unintended commands or code to be executed, allow sensitive data to be read or modified, or could cause other unintended behavior through malicious package names.

References

  • a966e781499ff6fd4eea66876d7532301b13a382

For more information

If you have any questions or comments about this advisory:

Пакеты

Наименование

APKLeaks

pip
Затронутые версииВерсия исправления

< 2.0.4

2.0.4

EPSS

Процентиль: 77%
0.01049
Низкий

9.3 Critical

CVSS3

Дефекты

CWE-78
CWE-88

Связанные уязвимости

CVSS3: 9.3
nvd
почти 5 лет назад

APKLeaks is an open-source project for scanning APK file for URIs, endpoints & secrets. APKLeaks prior to v2.0.3 allows remote attackers to execute arbitrary OS commands via package name inside application manifest. An attacker could include arguments that allow unintended commands or code to be executed, allow sensitive data to be read or modified or could cause other unintended behavior through malicious package name. The problem is fixed in version v2.0.6-dev and above.

EPSS

Процентиль: 77%
0.01049
Низкий

9.3 Critical

CVSS3

Дефекты

CWE-78
CWE-88