CVE-2021-21385
Summary
| CVE | CVE-2021-21385 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-03-24 21:15:00 UTC |
| Updated | 2021-03-30 18:30:00 UTC |
| Description | Mifos-Mobile Android Application for MifosX is an Android Application built on top of the MifosX Self-Service platform. Mifos-Mobile before commit e505f62 disables HTTPS hostname verification of its HTTP client. Additionally it accepted any self-signed certificate as valid. Hostname verification is an important part when using HTTPS to ensure that the presented certificate is valid for the host. Disabling it can allow for man-in-the-middle attacks. Accepting any certificate, even self-signed ones allows man-in-the-middle attacks. This problem is fixed in mifos-mobile commit e505f62. |
Risk And Classification
Problem Types: CWE-295 | CWE-297
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Mifos | Mifos-mobile | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Mobile Applications | Mifos Mobile Apps | MISC | openmf.github.io | |
| Merge pull request from GHSA-9657-33wf-rmvx · openMF/mifos-mobile@e505f62 · GitHub | MISC | github.com | |
| Disabled hostname verification and accepting self-signed certificates · Advisory · openMF/mifos-mobile · GitHub | CONFIRM | github.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.