CVE-2012-6637
Apache Cordova 3.3.0 and earlier and Adobe PhoneGap 2.9.0 and earlier do not anchor the end of domain-name regular expressions, which allows remote attackers to bypass a whitelist protection mechanism via a domain name that contains an acceptable name…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (8.77%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Apache Cordova 3.3.0 and earlier and Adobe PhoneGap 2.9.0 and earlier do not anchor the end of domain-name regular expressions, which allows remote attackers to bypass a whitelist protection mechanism via a domain name that contains an acceptable name as an initial substring.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 8.77% probability · 95th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20
- Affected
- apache/cordova · adobe/phonegap
- Source
- cve@mitre.org
References
- http://labs.mwrinfosecurity.com/blog/2012/04/30/building-android-javajavascript-bridges/
- http://openwall.com/lists/oss-security/2014/02/07/9
- http://packetstormsecurity.com/files/124954/apachecordovaphonegap-bypass.txt
- http://seclists.org/bugtraq/2014/Jan/96Patch
- http://www.cs.utexas.edu/~shmat/shmat_ndss14nofrak.pdfExploit
- http://www.internetsociety.org/ndss2014/programme#session3
- http://labs.mwrinfosecurity.com/blog/2012/04/30/building-android-javajavascript-bridges/
- http://openwall.com/lists/oss-security/2014/02/07/9
- http://packetstormsecurity.com/files/124954/apachecordovaphonegap-bypass.txt
- http://seclists.org/bugtraq/2014/Jan/96Patch
- http://www.cs.utexas.edu/~shmat/shmat_ndss14nofrak.pdfExploit
- http://www.internetsociety.org/ndss2014/programme#session3
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.