CVE-2014-0073
The CDVInAppBrowser class in the Apache Cordova In-App-Browser standalone plugin (org.apache.cordova.inappbrowser) before 0.3.2 for iOS and the In-App-Browser plugin for iOS from Cordova 2.6.0 through 2.9.0 does not properly validate callback…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (8.28%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The CDVInAppBrowser class in the Apache Cordova In-App-Browser standalone plugin (org.apache.cordova.inappbrowser) before 0.3.2 for iOS and the In-App-Browser plugin for iOS from Cordova 2.6.0 through 2.9.0 does not properly validate callback identifiers, which allows remote attackers to execute arbitrary JavaScript in the host page and consequently gain privileges via a crafted gap-iab: URI.
- CVSS 3.0
- 9.8 CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 8.28% probability · 95th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- apache/cordova in-app-browser · apache/cordova
- Source
- secalert@redhat.com
References
- http://d3adend.org/blog/?p=403Issue Tracking, Third Party Advisory
- http://seclists.org/fulldisclosure/2014/Mar/30Mailing List, Third Party Advisory
- http://www.securityfocus.com/archive/1/531334/100/0/threaded
- http://www.securityfocus.com/bid/65959Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/91560Issue Tracking, Third Party Advisory, VDB Entry
- https://github.com/apache/cordova-plugin-inappbrowser/commit/26702cb0720c5c394b407c23570136c53171fa55Issue Tracking, Patch, Vendor Advisory
- https://mail-archives.apache.org/mod_mbox/cordova-dev/201403.mbox/%3CCAK_TSXLGJag5Q9ATUCbFtkWvMWX9XnC80kKp-HKi25gPcvV4gw%40mail.gmail.com%3E
- http://d3adend.org/blog/?p=403Issue Tracking, Third Party Advisory
- http://seclists.org/fulldisclosure/2014/Mar/30Mailing List, Third Party Advisory
- http://www.securityfocus.com/archive/1/531334/100/0/threaded
- http://www.securityfocus.com/bid/65959Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/91560Issue Tracking, Third Party Advisory, VDB Entry
- https://github.com/apache/cordova-plugin-inappbrowser/commit/26702cb0720c5c394b407c23570136c53171fa55Issue Tracking, Patch, Vendor Advisory
- https://mail-archives.apache.org/mod_mbox/cordova-dev/201403.mbox/%3CCAK_TSXLGJag5Q9ATUCbFtkWvMWX9XnC80kKp-HKi25gPcvV4gw%40mail.gmail.com%3E
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.