CVE-2014-0072
ios/CDVFileTransfer.m in the Apache Cordova File-Transfer standalone plugin (org.apache.cordova.file-transfer) before 0.4.2 for iOS and the File-Transfer plugin for iOS from Cordova 2.4.0 through 2.9.0 might allow remote attackers to spoof SSL servers…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (7.72%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
ios/CDVFileTransfer.m in the Apache Cordova File-Transfer standalone plugin (org.apache.cordova.file-transfer) before 0.4.2 for iOS and the File-Transfer plugin for iOS from Cordova 2.4.0 through 2.9.0 might allow remote attackers to spoof SSL servers by leveraging a default value of true for the trustAllHosts option.
- CVSS 3.0
- 7.5 HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
- EPSS
- 7.72% probability · 94th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20
- Affected
- apache/cordova file transfer · apache/cordova
- Source
- secalert@redhat.com
References
- http://d3adend.org/blog/?p=403Issue Tracking, Third Party Advisory
- http://seclists.org/fulldisclosure/2014/Mar/29Mailing List, Third Party Advisory
- http://www.securityfocus.com/archive/1/531335/100/0/threaded
- https://exchange.xforce.ibmcloud.com/vulnerabilities/91561Issue Tracking, Third Party Advisory, VDB Entry
- https://github.com/apache/cordova-plugin-file-transfer/commit/a1d6fc07e8a40c1b2b16f4103c403b30e1089668Issue Tracking, Patch, Vendor Advisory
- https://mail-archives.apache.org/mod_mbox/cordova-dev/201403.mbox/%3CCAK_TSXKL9JtkehHC0jEoRwdvVKXt-d5uj40EwNY-Gk3ttX=wJw%40mail.gmail.com%3E
- http://d3adend.org/blog/?p=403Issue Tracking, Third Party Advisory
- http://seclists.org/fulldisclosure/2014/Mar/29Mailing List, Third Party Advisory
- http://www.securityfocus.com/archive/1/531335/100/0/threaded
- https://exchange.xforce.ibmcloud.com/vulnerabilities/91561Issue Tracking, Third Party Advisory, VDB Entry
- https://github.com/apache/cordova-plugin-file-transfer/commit/a1d6fc07e8a40c1b2b16f4103c403b30e1089668Issue Tracking, Patch, Vendor Advisory
- https://mail-archives.apache.org/mod_mbox/cordova-dev/201403.mbox/%3CCAK_TSXKL9JtkehHC0jEoRwdvVKXt-d5uj40EwNY-Gk3ttX=wJw%40mail.gmail.com%3E
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.