PT-2021-14465 · Unknown · Mifos-Mobile

Published

2021-03-24

·

Updated

2021-03-30

·

CVE-2021-21385

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Mifos-Mobile versions before commit e505f62
Description The Mifos-Mobile Android Application for MifosX has a security issue where it disables HTTPS hostname verification of its HTTP client and accepts any self-signed certificate as valid. This lack of verification can allow for man-in-the-middle attacks, as it does not ensure that the presented certificate is valid for the host. The issue is related to the improper handling of HTTPS connections, which can compromise the security of the application.
Recommendations For versions before commit e505f62, update to a version that includes the fix commit e505f62 to resolve the issue. As a temporary workaround, consider restricting the use of the application in unsecured networks to minimize the risk of exploitation.

Fix

Improper Certificate Validation

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-21385
GHSA-9657-33WF-RMVX

Affected Products

Mifos-Mobile