PT-2024-24747 · Jadx · Jadx

0X33C0Unt

·

Published

2024-04-22

·

Updated

2024-04-23

·

CVE-2024-32653

CVSS v3.1

6.1

Medium

VectorAV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:H
Name of the Vulnerable Software and Affected Versions jadx versions prior to 1.5.0
Description The issue concerns a Dex to Java decompiler where the package name is not filtered before concatenation, allowing an attacker to inject arbitrary code into the package name. This can be exploited to execute commands with shell privileges.
Recommendations For versions prior to 1.5.0, update to version 1.5.0 to resolve the issue. As a temporary workaround, consider filtering package names manually before concatenation to minimize the risk of exploitation.

Exploit

Fix

RCE

Weakness Enumeration

Related Identifiers

CVE-2024-32653
GHSA-3PP3-HG2Q-9GPM

Affected Products

Jadx