Apache Cordova White List Bypass Vulnerability (CVE-2015-5256)
Apache Cordova White List Bypass Vulnerability (CVE-2015-5256)
Release date:
Updated on:
Affected Systems:
Apache Group Cordova <= 3.7.2
Description:
CVE (CAN) ID: CVE-2015-5256
Cordova uses HTML, CSS, and JavaScript to build a mobile app on the local machine.
The whitelist of Cordova Android 3.7.2 and earlier versions does not apply correctly. The security vulnerability exists. Attackers can bypass the whitelist and execute arbitrary Javascript using a specially crafted URI.
<* Source: Muneaki Nishimura
Link: http://seclists.org/bugtraq/2015/Nov/105
*>
Suggestion:
Vendor patch:
Apache Group
------------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://cordova.apache.org/
This article permanently updates the link address: