Ecosyste.ms: Advisories

An open API service providing security vulnerability metadata for many open source software ecosystems.

Security Advisories: GSA_kwCzR0hTQS04NDM0LXY3eHctOG05eM0loA

Improper Neutralization of Argument Delimiters in a Decompiling Package Process in APKLeaks

APKLeaks prior to v2.0.4 allows remote authenticated attackers to execute arbitrary OS commands via package name inside the application manifest.

Impact

An authenticated attacker could include arguments that allow unintended commands or code to be executed, allow sensitive data to be read or modified, or could cause other unintended behavior through malicious package names.

References

For more information

If you have any questions or comments about this advisory:

Permalink: https://github.com/advisories/GHSA-8434-v7xw-8m9x
JSON: https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS04NDM0LXY3eHctOG05eM0loA
Source: GitHub Advisory Database
Origin: Unspecified
Severity: Critical
Classification: General
Published: over 2 years ago
Updated: 8 months ago


CVSS Score: 9.3
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N

Identifiers: GHSA-8434-v7xw-8m9x, CVE-2021-21386
References: Repository: https://github.com/dwisiswant0/apkleaks
Blast Radius: 0.0

Affected Packages

pypi:APKLeaks
Dependent packages: 0
Dependent repositories: 1
Downloads: 1,533 last month
Affected Version Ranges: < 2.0.4
Fixed in: 2.0.4
All affected versions:
All unaffected versions: 2.2.0, 2.3.0, 2.3.1, 2.3.2, 2.4.0, 2.5.0, 2.5.1, 2.5.2, 2.6.0, 2.6.1