PT-2021-14465 · Unknown · Mifos-Mobile
Published
2021-03-24
·
Updated
2021-03-30
·
CVE-2021-21385
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Mifos-Mobile versions before commit e505f62
Description
The Mifos-Mobile Android Application for MifosX has a security issue where it disables HTTPS hostname verification of its HTTP client and accepts any self-signed certificate as valid. This lack of verification can allow for man-in-the-middle attacks, as it does not ensure that the presented certificate is valid for the host. The issue is related to the improper handling of HTTPS connections, which can compromise the security of the application.
Recommendations
For versions before commit e505f62, update to a version that includes the fix commit e505f62 to resolve the issue. As a temporary workaround, consider restricting the use of the application in unsecured networks to minimize the risk of exploitation.
Fix
Improper Certificate Validation
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Mifos-Mobile