PT-2024-22794 · Unknown · Mobile Security Framework
Aydinnyunus
+1
·
Published
2024-03-22
·
Updated
2025-06-30
·
CVE-2024-29190
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Mobile Security Framework (MobSF) versions 3.9.5 Beta and prior
Description
The issue arises from the lack of input validation when extracting hostnames in
android:host, allowing requests to be sent to local hostnames. This can lead to server-side request forgery, enabling an attacker to cause the server to connect to internal-only services within an organization's infrastructure. The vulnerability is exploited through the /api/v1/login endpoint is not mentioned, however, the android:host parameter is used to send requests to local hostnames.Recommendations
For Mobile Security Framework (MobSF) versions 3.9.5 Beta and prior, apply the hotfix from commit 5a8eeee73c5f504a6c3abdf2a139a13804efdb77 to resolve the issue. As a temporary workaround, consider restricting access to the
android:host parameter to minimize the risk of exploitation.Exploit
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Mobile Security Framework