QID 630691

Date Published: 2021-06-15

QID 630691: WhatsApp For Android Relative Path Traversal Vulnerability

A lack of filename validation when unzipping archives prior to WhatsApp for Android v2.21.8.13 and WhatsApp Business for Android v2.21.8.13 could have allowed path traversal attacks that overwrite WhatsApp files.

On successful exploitation, it could allow an attacker to execute code.

  • CVSS V3 rated as High - 7.4 severity.
  • CVSS V2 rated as High - 7.5 severity.
  • Solution
    Upgrade to the latest packages which contain a patch. Refer to CVE-2021-24035 to address this issue and obtain more information.
    Vendor References

    CVEs related to QID 630691

    Software Advisories
    Advisory ID Software Component Link
    CVE-2021-24035 Android URL Logo nvd.nist.gov/vuln/detail/CVE-2021-24035