Junglewise Threat Intelligence

CVE-2023-42261: PYSEC-2023-310 - Mobile Security Framework (MobSF) <=v3.7.8 Beta is vulnerable to Insecure Permissions. NOTE: the vendor's position is that authentication is

CVE-2023-42261 · Severity: low · CVSS 3.1 · Published 2023-09-21

Technologies: mobsf (PyPI). Vendors: PyPI.

Executive brief

Mobile Security Framework (MobSF) <=v3.7.8 Beta is vulnerable to Insecure Permissions. NOTE: the vendor's position is that authentication is intentionally not implemented because the product is not intended for an untrusted network environment. Use cases requiring authentication could, for example, use a reverse proxy server.

Affected products

  • PyPI mobsf

Related threats