CVE-2024-43399
Last modified
CVE-2024-43399 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. Mobile Security Framework (MobSF) is a pen-testing, malware analysis and security assessment framework capable of performing static and dynamic analysis. Before 4.0.7, there is a flaw in the Static Libraries analysis section. EPSS estimates a 0.90% chance of exploitation in the next 30 days.
Description
Mobile Security Framework (MobSF) is a pen-testing, malware analysis and security assessment framework capable of performing static and dynamic analysis. Before 4.0.7, there is a flaw in the Static Libraries analysis section. Specifically, during the extraction of .a extension files, the measure intended to prevent Zip Slip attacks is improperly implemented. Since the implemented measure can be bypassed, the vulnerability allows an attacker to extract files to any desired location within the server running MobSF. This vulnerability is fixed in 4.0.7.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Opensecurity | Mobile Security Framework | < 4.0.7 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2024-43399?
How severe is CVE-2024-43399?
How do I fix CVE-2024-43399?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-43393A low privileged remote attacker can perform configuration c…8.1
- CVE-2024-43394Server-Side Request Forgery (SSRF) in Apache HTTP Server on …7.5
- CVE-2024-43395CraftOS-PC 2 is a rewrite of the desktop port of CraftOS fro…8.2
- CVE-2024-43396Khoj is an application that creates personal AI agents. The …5.4
- CVE-2024-43397Apollo is a configuration management system. A vulnerability…4.3
- CVE-2024-43398REXML is an XML toolkit for Ruby. The REXML gem before 3.3.6…5.9
- CVE-2024-4340Passing a heavily nested list to sqlparse.parse() leads to a…7.5
- CVE-2024-43400XWiki Platform is a generic wiki platform offering runtime s…5.4
- CVE-2024-43401XWiki Platform is a generic wiki platform offering runtime s…8
- CVE-2024-43402Rust is a programming language. The fix for CVE-2024-24576, …8.8
- CVE-2024-43403Kanister is a data protection workflow management tool. The …8.8
- CVE-2024-43404MEGABOT is a fully customized Discord bot for learning and f…9.8
Are you affected by CVE-2024-43399?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
