CVE-2024-31215

MEDIUM

Opensecurity Mobile Security Framework < 3.9.8 - SSRF

Title source: rule
STIX 2.1

Description

Mobile Security Framework (MobSF) is a security research platform for mobile applications in Android, iOS and Windows Mobile. A SSRF vulnerability in firebase database check logic. The attacker can cause the server to make a connection to internal-only services within the organization’s infrastructure. When a malicious app is uploaded to Static analyzer, it is possible to make internal requests. This vulnerability has been patched in version 3.9.8.

Scores

CVSS v3 6.3
EPSS 0.0014
EPSS Percentile 33.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-918
Status published
Products (2)
opensecurity/mobile_security_framework < 3.9.8
pypi/mobsf 0 - 3.9.8PyPI
Published Apr 04, 2024
Tracked Since Feb 18, 2026