Apache Cordova Android before 3.5.1 allows remote attackers to bypass the HTTP whitelist and connect to arbitrary servers by using JavaScript to open WebSocket connections through WebView.
References
Configurations
History
21 Nov 2024, 02:08
Type | Values Removed | Values Added |
---|---|---|
References | () http://cordova.apache.org/announcements/2014/08/04/android-351.html - Vendor Advisory | |
References | () http://www.securityfocus.com/bid/69041 - |
Information
Published : 2014-11-15 21:59
Updated : 2024-11-21 02:08
NVD link : CVE-2014-3501
Mitre link : CVE-2014-3501
CVE.ORG link : CVE-2014-3501
JSON object : View
Products Affected
apache
- cordova
CWE
CWE-254
7PK - Security Features