Skip to content

New MASWE for Diry Stream Vulnerability (Android only) #171

Description

@sushi2k

We would need to discuss if we create a new MASWE for this vulnerability (like Strandhogg - https://mas.owasp.org/MASWE/MASVS-PLATFORM/MASWE-0057/) or simply add it as another test to MASWE-0064 (https://mas.owasp.org/MASWE/MASVS-PLATFORM/MASWE-0064/).

I think MASWE-0064 should only cover tests where an app is offering a content provider and how to implement it securely.

In the case of a Dirty Stream attack a content provider is offered by a malicious app and the victim app can be abused by Path Traversal to store a malicious file in the apps sandbox or overwrite existing files. So a separate MASWE for Dirty Stream would make sense.

See also OWASP/mastg#3768

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or request

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions