Skip to content

Improper Neutralization of Argument Delimiters in a Decompiling Package Process

Moderate
dwisiswant0 published GHSA-8434-v7xw-8m9x Mar 19, 2021

Package

APKLeaks (APKLeaks module)

Affected versions

< v2.0.3

Patched versions

v2.0.6-dev

Description

APKLeaks prior to v2.0.3 allows remote authenticated attackers to execute arbitrary OS commands via package name inside the application manifest.

Impact

An authenticated attacker could include arguments that allow unintended commands or code to be executed, allow sensitive data to be read or modified, or could cause other unintended behavior through malicious package names.

Patches

The problem is fixed in v2.0.6-dev and above.

Workarounds

Upgrade to version 2.0.6-dev onwards.

References

For more information

If you have any questions or comments about this advisory:

Severity

Moderate
4.8
/ 10

CVSS base metrics

Attack vector
Local
Attack complexity
Low
Privileges required
Low
User interaction
Required
Scope
Unchanged
Confidentiality
Low
Integrity
Low
Availability
Low
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L

CVE ID

CVE-2021-21386

Credits