Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-cc8j-6phr-jv9x

Опубликовано: 22 сент. 2023
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

Withdrawn Advisory: Mobile Security Framework (MobSF) Vulnerable to Insecure Permissions

Withdrawn Advisory

This advisory has been withdrawn because the vendor's position is that authentication is intentionally not implemented because the product is not intended for an untrusted network environment. Use cases requiring authentication could, for example, use a reverse proxy server.

Original Description

Mobile Security Framework (MobSF) <=v3.7.8 Beta is vulnerable to Insecure Permissions.

Пакеты

Наименование

mobsf

pip
Затронутые версииВерсия исправления

< 3.9.7

3.9.7

EPSS

Процентиль: 37%
0.0016
Низкий

7.5 High

CVSS3

Дефекты

CWE-276

Связанные уязвимости

CVSS3: 7.5
nvd
больше 2 лет назад

Mobile Security Framework (MobSF) <=v3.7.8 Beta is vulnerable to Insecure Permissions. NOTE: the vendor's position is that authentication is intentionally not implemented because the product is not intended for an untrusted network environment. Use cases requiring authentication could, for example, use a reverse proxy server.

EPSS

Процентиль: 37%
0.0016
Низкий

7.5 High

CVSS3

Дефекты

CWE-276