Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-21386

Опубликовано: 24 мар. 2021
Источник: nvd
CVSS3: 9.3
CVSS3: 9.8
CVSS2: 10
EPSS Низкий

Описание

APKLeaks is an open-source project for scanning APK file for URIs, endpoints & secrets. APKLeaks prior to v2.0.3 allows remote attackers to execute arbitrary OS commands via package name inside application manifest. An attacker could include arguments that allow unintended commands or code to be executed, allow sensitive data to be read or modified or could cause other unintended behavior through malicious package name. The problem is fixed in version v2.0.6-dev and above.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:apkleaks_project:apkleaks:*:*:*:*:*:*:*:*
Версия до 2.0.3 (исключая)

EPSS

Процентиль: 77%
0.01049
Низкий

9.3 Critical

CVSS3

9.8 Critical

CVSS3

10 Critical

CVSS2

Дефекты

CWE-78

Связанные уязвимости

CVSS3: 9.3
github
около 4 лет назад

Improper Neutralization of Argument Delimiters in a Decompiling Package Process in APKLeaks

EPSS

Процентиль: 77%
0.01049
Низкий

9.3 Critical

CVSS3

9.8 Critical

CVSS3

10 Critical

CVSS2

Дефекты

CWE-78