Apache Cordova iOS Security Restriction Bypass and resource loading Vulnerability (CVE-2015-5207)
Apache Cordova iOS Security Restriction Bypass and resource loading Vulnerability (CVE-2015-5207)
Release date:
Updated on:
Affected Systems:
Apache Group Cordova iOS <4.0.0
Description:
CVE (CAN) ID: CVE-2015-5207
Apache Cordova is the library used to create a local mobile application.
Apache Cordova versions earlier than iOS 4.0.0 have a security vulnerability that allows attackers to bypass the URL whitelist protection mechanism in the application and load arbitrary resources.
<* Source: Muneaki Nishimura
*>
Suggestion:
Vendor patch:
Apache Group
------------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Https://cordova.apache.org/announcements/2016/04/27/security.html
This article permanently updates the link address: