Skip to content
Appaloosa Scout

Vulnerability · NVD

CVE-2021-24035

CRITICAL 9.1

A lack of filename validation when unzipping archives prior to WhatsApp for Android v2.21.8.13 and WhatsApp Business for Android v2.21.8.13 could have allowed path traversal attacks that overwrite WhatsApp files.

Attack vector : Network No privileges required No user interaction
Show raw CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
EPSS 1.13% above median percentile 63.5%

Tracked apps referencing this CVE

For each app: the affected range, the fixing version, and where the tracked app stands today.

Vulnerable CPE configurations (2)
Vendor Product Versions
whatsapp whatsapp
Android
<2.21.8.13
whatsapp whatsapp_business
Android
<2.21.8.13
View on NVD ↗ Advisory · www.whatsapp.com