PT-2021-14466 · Apkleaks · Apkleaks

Ry0Tak

·

Published

2021-03-24

·

Updated

2022-01-21

·

CVE-2021-21386

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions APKLeaks versions prior to 2.0.6-dev
Description APKLeaks is an open-source project for scanning APK files for URIs, endpoints, and secrets. The issue allows remote attackers to execute arbitrary OS commands via the package name inside the application manifest. An attacker could include arguments that allow unintended commands or code to be executed, allow sensitive data to be read or modified, or could cause other unintended behavior through malicious package name.
Recommendations For versions prior to 2.0.6-dev, update to version 2.0.6-dev or above to resolve the issue. As a temporary workaround, consider restricting the use of the package name inside the application manifest to minimize the risk of exploitation.

Fix

Argument Injection

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-21386
GHSA-8434-V7XW-8M9X

Affected Products

Apkleaks