CVE-2025-31116
MEDIUM4.4EPSS 0.16%Mobile Security Framework (MobSF) has a SSRF Vulnerability fix bypass on assetlinks_check with DNS Rebinding
發布日:2025/3/31修改日:2026/2/4
描述
Mobile Security Framework (MobSF) is a pen-testing, malware analysis and security assessment framework capable of performing static and dynamic analysis. The mitigation for CVE-2024-29190 in valid_host() uses socket.gethostbyname(), which is vulnerable to SSRF abuse using DNS rebinding technique. This vulnerability is fixed in 4.3.2.
受影響套件(2)
- PyPI/mobsffrom 0, < 4.3.2
- PyPI/mobsffrom 0, < 4b8bab5a9858c69fe13be4631b82d82186e0d3bd | from 0, < 4.3.2
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM4.4 | CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:N/A:L |
參考連結(5)
- ADVISORYhttps://nvd.nist.gov/vuln/detail/CVE-2025-31116
- PATCHhttps://github.com/MobSF/Mobile-Security-Framework-MobSF
- WEBhttps://github.com/MobSF/Mobile-Security-Framework-MobSF/commit/4b8bab5a9858c69fe13be4631b82d82186e0d3bd
- WEBhttps://github.com/MobSF/Mobile-Security-Framework-MobSF/security/advisories/GHSA-fcfq-m8p6-gw56
- WEBhttps://github.com/pypa/advisory-database/tree/main/vulns/mobsf/PYSEC-2025-48.yaml