Release date:
Updated on:
Affected Systems:
Apache Group Cordova 2.6.0-2.9.0
Description:
--------------------------------------------------------------------------------
Bugtraq id: 65967
CVE (CAN) ID: CVE-2014-0072
Cordova InAppBrowser is a Web browser displayed in the application when you use window. open call.
Cordova File-Transfer iOS plug-in and Cordova File-Transfer iOS single-host plug-in (org. apache. cordova. in file-transfer) 0.1.0-0.4.1, the default value of trustAllHosts is set to true on iOS, and a remote security vulnerability exists in implementation. Details are unknown.
<* Source: Neil Bergman
Link: http://www.securityfocus.com/archive/1/531335
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Apache Group
------------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://cordova.apache.org/docs/en/2.4.0/cordova_inappbrowser_inappbrowser.md.html