Withdrawn Advisory: Mobile Security Framework (MobSF) Vulnerable to Insecure Permissions
High severity
GitHub Reviewed
Published
Sep 22, 2023
to the GitHub Advisory Database
•
Updated Apr 10, 2025
Withdrawn
This advisory was withdrawn on Apr 10, 2025
Description
Published by the National Vulnerability Database
Sep 21, 2023
Published to the GitHub Advisory Database
Sep 22, 2023
Reviewed
Apr 10, 2025
Withdrawn
Apr 10, 2025
Last updated
Apr 10, 2025
Withdrawn Advisory
This advisory has been withdrawn because the vendor's position is that authentication is intentionally not implemented because the product is not intended for an untrusted network environment. Use cases requiring authentication could, for example, use a reverse proxy server.
Original Description
Mobile Security Framework (MobSF) <=v3.7.8 Beta is vulnerable to Insecure Permissions.
References