VDB
EN

PYSEC-2024-256

상세

Mobile Security Framework (MobSF) is a pen-testing, malware analysis and security assessment framework capable of performing static and dynamic analysis. In versions prior to 3.9.7, the requests.get() request in the _check_url method is specified as allow_redirects=True, which allows a server-side request forgery when a request to .well-known/assetlinks.json" returns a 302 redirect. This is a bypass of the fix for CVE-2024-29190 and is fixed in 3.9.7.

이 버전이 영향받나요?

사용 중인 패키지 버전을 입력하면 즉시 평가합니다.

영향 패키지

PyPI / mobsf
최초 영향 버전: 0 수정 버전: f22c584aa7d43527970c9da61eb678953cfc0a8e
수정 pip install --upgrade 'mobsf>=f22c584aa7d43527970c9da61eb678953cfc0a8e'

참고