CVE-2024-41955: Mobile Security Framework (MobSF) has an Open Redirect in Login Redirect
Impact What kind of vulnerability is it? Who is impacted?
An open redirect vulnerability exist in MobSF authentication view.
PoC 1. Go to http://127.0.0.1:8000/login/?next=//afine.com in a web browser. 2. Enter credentials and press "Sign In". 3. You will be redirected to afine.com
Users who are not using authentication are not impacted.
Patches Has the problem been patched? What versions should users upgrade to?
Update to MobSF v4.0.5
Workarounds Is there a way for users to fix or remediate the vulnerability without upgrading? Disable Authentication
References Are there any links users can visit to find out more? Fix: https://github.com/MobSF/Mobile-Security-Framework-MobSF/commit/fdaad81314f393d324c1ede79627e9d47986c8c8
Reporter Marcin Węgłowski (AFINE Team)
Other sources
Mobile Security Framework (MobSF) is a security research platform for mobile applications in Android, iOS and Windows Mobile. An open redirect vulnerability exist in MobSF authentication view. Update to MobSF v4.0.5.
— MITRE
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-41955?
CVE-2024-41955 has been classified as a medium severity vulnerability.
What type of vulnerability is CVE-2024-41955?
CVE-2024-41955 is an open redirect vulnerability affecting MobSF authentication views.
Who is impacted by CVE-2024-41955?
Users of MobSF versions prior to 4.0.5 are impacted by CVE-2024-41955.
How do I fix CVE-2024-41955?
To fix CVE-2024-41955, upgrade MobSF to version 4.0.5 or higher.
What software versions are affected by CVE-2024-41955?
CVE-2024-41955 affects MobSF versions prior to 4.0.5.