CVE-2024-31215
MEDIUMOpensecurity Mobile Security Framework < 3.9.8 - SSRF
Title source: ruleDescription
Mobile Security Framework (MobSF) is a security research platform for mobile applications in Android, iOS and Windows Mobile. A SSRF vulnerability in firebase database check logic. The attacker can cause the server to make a connection to internal-only services within the organization’s infrastructure. When a malicious app is uploaded to Static analyzer, it is possible to make internal requests. This vulnerability has been patched in version 3.9.8.
References (3)
Core 3
Core References
Vendor Advisory x_refsource_confirm
https://github.com/MobSF/Mobile-Security-Framework-MobSF/security/advisories/GHSA-wpff-wm84-x5cx
Issue Tracking, Patch x_refsource_misc
https://github.com/MobSF/Mobile-Security-Framework-MobSF/pull/2373
Scores
CVSS v3
6.3
EPSS
0.0014
EPSS Percentile
33.3%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-918
Status
published
Products (2)
opensecurity/mobile_security_framework
< 3.9.8
pypi/mobsf
0 - 3.9.8PyPI
Published
Apr 04, 2024
Tracked Since
Feb 18, 2026