PT-2024-24747 · Jadx · Jadx
0X33C0Unt
·
Published
2024-04-22
·
Updated
2024-04-23
·
CVE-2024-32653
CVSS v3.1
6.1
Medium
| Vector | AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:H |
Name of the Vulnerable Software and Affected Versions
jadx versions prior to 1.5.0
Description
The issue concerns a Dex to Java decompiler where the package name is not filtered before concatenation, allowing an attacker to inject arbitrary code into the package name. This can be exploited to execute commands with shell privileges.
Recommendations
For versions prior to 1.5.0, update to version 1.5.0 to resolve the issue. As a temporary workaround, consider filtering package names manually before concatenation to minimize the risk of exploitation.
Exploit
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Jadx