VulnerabilityModified
CVE-2014-3501
Apache Cordova Android before 3.5.1 allows remote attackers to bypass the HTTP whitelist and connect to arbitrary servers by using JavaScript to open WebSocket connections through WebView.
MEDIUM 4.3EPSS 3.75%
Does this matter?
Lower severity and a low EPSS score (3.75%). Track it; it rarely justifies an emergency change on its own.
Description
Apache Cordova Android before 3.5.1 allows remote attackers to bypass the HTTP whitelist and connect to arbitrary servers by using JavaScript to open WebSocket connections through WebView.
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
- EPSS
- 3.75% probability · 89th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-254
- Affected
- apache/cordova
- Source
- secalert@redhat.com
References
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.