CVE-2021-21385
Disabling it can allow for man-in-the-middle attacks.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.70%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Mifos-Mobile Android Application for MifosX is an Android Application built on top of the MifosX Self-Service platform. Mifos-Mobile before commit e505f62 disables HTTPS hostname verification of its HTTP client. Additionally it accepted any self-signed certificate as valid. Hostname verification is an important part when using HTTPS to ensure that the presented certificate is valid for the host. Disabling it can allow for man-in-the-middle attacks. Accepting any certificate, even self-signed ones allows man-in-the-middle attacks. This problem is fixed in mifos-mobile commit e505f62.
- CVSS 3.1
- 7.4 HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
- EPSS
- 0.70% probability · 51th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-295, CWE-297
- Affected
- mifos/mifos-mobile
- Source
- security-advisories@github.com
References
- https://github.com/openMF/mifos-mobile/commit/e505f62b92b19292bfdabd6e996ab76abfeaa90dPatch, Third Party Advisory
- https://github.com/openMF/mifos-mobile/security/advisories/GHSA-9657-33wf-rmvxPatch, Third Party Advisory
- https://openmf.github.io/mobileapps.github.io/Product, Third Party Advisory
- https://github.com/openMF/mifos-mobile/commit/e505f62b92b19292bfdabd6e996ab76abfeaa90dPatch, Third Party Advisory
- https://github.com/openMF/mifos-mobile/security/advisories/GHSA-9657-33wf-rmvxPatch, Third Party Advisory
- https://openmf.github.io/mobileapps.github.io/Product, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.