Apache Cordova 3.7.2 Whitelist Failure

Discussion in 'News Aggregator' started by Packet Storm, 24 Nov 2015.

  1. Packet Storm

    Packet Storm Guest

    Android applications created using Apache Cordova that use a remote server contain a vulnerability where whitelist restrictions are not properly applied. Improperly crafted URIs could be used to circumvent the whitelist, allowing for the execution of non-whitelisted Javascript. Versions 3.7.2 and below are affected.

    Continue reading...
     

Share This Page

Loading...