Описание
MobSF is a mobile application security testing tool used. Typically, MobSF is deployed on centralized internal or cloud-based servers that also host other security tools and web applications. Access to the MobSF web interface is often granted to internal security teams, audit teams, and external vendors. MobSF provides a feature that allows users to upload ZIP files for static analysis. Upon upload, these ZIP files are automatically extracted and stored within the MobSF directory. However, in versions up to and including 4.3.2, this functionality lacks a check on the total uncompressed size of the ZIP file, making it vulnerable to a ZIP of Death (zip bomb) attack. Due to the absence of safeguards against oversized extractions, an attacker can craft a specially prepared ZIP file that is small in compressed form but expands to a massive size upon extraction. Exploiting this, an attacker can exhaust the server's disk space, leading to a complete denial of service (DoS) not just for MobSF
Уязвимые конфигурации
EPSS
6.8 Medium
CVSS3
6.5 Medium
CVSS3
Дефекты
Связанные уязвимости
Mobile Security Framework (MobSF) Allows Web Server Resource Exhaustion via ZIP of Death Attack
EPSS
6.8 Medium
CVSS3
6.5 Medium
CVSS3