Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-46730

Опубликовано: 05 мая 2025
Источник: nvd
CVSS3: 6.8
CVSS3: 6.5
EPSS Низкий

Описание

MobSF is a mobile application security testing tool used. Typically, MobSF is deployed on centralized internal or cloud-based servers that also host other security tools and web applications. Access to the MobSF web interface is often granted to internal security teams, audit teams, and external vendors. MobSF provides a feature that allows users to upload ZIP files for static analysis. Upon upload, these ZIP files are automatically extracted and stored within the MobSF directory. However, in versions up to and including 4.3.2, this functionality lacks a check on the total uncompressed size of the ZIP file, making it vulnerable to a ZIP of Death (zip bomb) attack. Due to the absence of safeguards against oversized extractions, an attacker can craft a specially prepared ZIP file that is small in compressed form but expands to a massive size upon extraction. Exploiting this, an attacker can exhaust the server's disk space, leading to a complete denial of service (DoS) not just for MobSF

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:opensecurity:mobile_security_framework:*:*:*:*:*:*:*:*
Версия до 4.3.3 (исключая)

EPSS

Процентиль: 29%
0.00107
Низкий

6.8 Medium

CVSS3

6.5 Medium

CVSS3

Дефекты

CWE-409

Связанные уязвимости

CVSS3: 6.8
github
9 месяцев назад

Mobile Security Framework (MobSF) Allows Web Server Resource Exhaustion via ZIP of Death Attack

EPSS

Процентиль: 29%
0.00107
Низкий

6.8 Medium

CVSS3

6.5 Medium

CVSS3

Дефекты

CWE-409