Path Traversal Vulnerability in WhatsApp and WhatsApp Business for Android
CVE-2021-24035

9.1CRITICAL

Key Information:

Vendor

Facebook

Vendor
CVE Published:
11 June 2021

What is CVE-2021-24035?

A vulnerability exists in WhatsApp for Android and WhatsApp Business for Android due to inadequate filename validation when extracting archives. This flaw could enable attackers to conduct path traversal attacks, potentially leading to overwriting files within the application. Users of affected versions should be cautious and consider updating to the latest versions to mitigate risk.

Affected Version(s)

WhatsApp Business for Android < unspecified

WhatsApp for Android < unspecified

References

CVSS V3.1

Score:
9.1
Severity:
CRITICAL
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2021-24035 : Path Traversal Vulnerability in WhatsApp and WhatsApp Business for Android