CVE-2024-32653 - CVE House
Back to Database
Status published Medium CVE-2024-32653

Insufficient input filtering of "package name" allows command execution in the device with shell privileges

Vulnerability Description

jadx is a Dex to Java decompiler. Prior to version 1.5.0, the package name is not filtered before concatenation. This can be exploited to inject arbitrary code into the package name. The vulnerability allows an attacker to execute commands with shell privileges. Version 1.5.0 contains a patch for the vulnerability.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-32653

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

jadx
Vulnerable Versions:
< 1.5.0

Timeline

Official Publish: April 22nd, 2024
Last Modified: August 2nd, 2024
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:H

Weaknesses (CWE)