Описание
Mobile Security Framework (MobSF) <=v3.7.8 Beta is vulnerable to Insecure Permissions. NOTE: the vendor's position is that authentication is intentionally not implemented because the product is not intended for an untrusted network environment. Use cases requiring authentication could, for example, use a reverse proxy server.
Ссылки
- Patch
- Issue TrackingVendor Advisory
- Issue TrackingVendor Advisory
- Exploit
- Patch
- Issue TrackingVendor Advisory
- Issue TrackingVendor Advisory
- Exploit
Уязвимые конфигурации
Конфигурация 1Версия до 3.7.6 (включая)
Одно из
cpe:2.3:a:opensecurity:mobile_security_framework:*:*:*:*:*:*:*:*
cpe:2.3:a:opensecurity:mobile_security_framework:3.7.8:beta:*:*:*:*:*:*
EPSS
Процентиль: 37%
0.0016
Низкий
7.5 High
CVSS3
Дефекты
CWE-276
Связанные уязвимости
CVSS3: 7.5
github
больше 2 лет назад
Withdrawn Advisory: Mobile Security Framework (MobSF) Vulnerable to Insecure Permissions
EPSS
Процентиль: 37%
0.0016
Низкий
7.5 High
CVSS3
Дефекты
CWE-276