PT-2014-4338 · Apache+1 · Apache Cordova+1
Martin Georgiev
+2
·
Published
2014-03-03
·
Updated
2014-03-03
·
CVE-2014-1881
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Apache Cordova versions 3.3.0 and earlier
Adobe PhoneGap versions 2.9.0 and earlier
Description
The issue allows remote attackers to bypass intended device-resource restrictions of an event-based bridge. This is achieved via a crafted library clone that leverages IFRAME script execution and waits a certain amount of time for an
OnJsPrompt handler return value as an alternative to correct synchronization.Recommendations
For Apache Cordova versions 3.3.0 and earlier, consider restricting access to the event-based bridge until a fix is available.
For Adobe PhoneGap versions 2.9.0 and earlier, avoid using the
OnJsPrompt handler in the affected library clone until the issue is resolved.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Phonegap
Apache Cordova