Ecosyste.ms: Advisories
An open API service providing security vulnerability metadata for many open source software ecosystems.
Security Advisories: GSA_kwCzR0hTQS04NDM0LXY3eHctOG05eM0loA
Improper Neutralization of Argument Delimiters in a Decompiling Package Process in APKLeaks
APKLeaks prior to v2.0.4 allows remote authenticated attackers to execute arbitrary OS commands via package name inside the application manifest.
Impact
An authenticated attacker could include arguments that allow unintended commands or code to be executed, allow sensitive data to be read or modified, or could cause other unintended behavior through malicious package names.
References
- a966e781499ff6fd4eea66876d7532301b13a382
For more information
If you have any questions or comments about this advisory:
- Email me at [email protected]
JSON: https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS04NDM0LXY3eHctOG05eM0loA
Source: GitHub Advisory Database
Origin: Unspecified
Severity: Critical
Classification: General
Published: over 2 years ago
Updated: 8 months ago
CVSS Score: 9.3
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N
Identifiers: GHSA-8434-v7xw-8m9x, CVE-2021-21386
References:
- https://github.com/dwisiswant0/apkleaks/security/advisories/GHSA-8434-v7xw-8m9x
- https://nvd.nist.gov/vuln/detail/CVE-2021-21386
- https://github.com/dwisiswant0/apkleaks/commit/a966e781499ff6fd4eea66876d7532301b13a382
- https://github.com/advisories/GHSA-8434-v7xw-8m9x
Blast Radius: 0.0
Affected Packages
pypi:APKLeaks
Dependent packages: 0Dependent repositories: 1
Downloads: 1,533 last month
Affected Version Ranges: < 2.0.4
Fixed in: 2.0.4
All affected versions:
All unaffected versions: 2.2.0, 2.3.0, 2.3.1, 2.3.2, 2.4.0, 2.5.0, 2.5.1, 2.5.2, 2.6.0, 2.6.1