VulnerabilityModified
CVE-2015-1835
Apache Cordova Android before 3.7.2 and 4.x before 4.0.2, when an application does not set explicit values in config.xml, allows remote attackers to modify undefined secondary configuration variables (preferences) via a crafted intent: URL.
MEDIUM 5.3EPSS 5.91%
Does this matter?
Lower severity and a low EPSS score (5.91%). Track it; it rarely justifies an emergency change on its own.
Description
Apache Cordova Android before 3.7.2 and 4.x before 4.0.2, when an application does not set explicit values in config.xml, allows remote attackers to modify undefined secondary configuration variables (preferences) via a crafted intent: URL.
- CVSS 3.0
- 5.3 MEDIUMCVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N
- EPSS
- 5.91% probability · 93th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20
- Affected
- apache/cordova
- Source
- secalert@redhat.com
References
- http://blog.trendmicro.com/trendlabs-security-intelligence/trend-micro-discovers-apache-vulnerability-that-allows-one-click-modification-of-android-apps/Exploit, Technical Description, Third Party Advisory
- http://www.securityfocus.com/bid/74866Third Party Advisory, VDB Entry
- https://cordova.apache.org/announcements/2015/05/26/android-402.htmlRelease Notes, Vendor Advisory
- http://blog.trendmicro.com/trendlabs-security-intelligence/trend-micro-discovers-apache-vulnerability-that-allows-one-click-modification-of-android-apps/Exploit, Technical Description, Third Party Advisory
- http://www.securityfocus.com/bid/74866Third Party Advisory, VDB Entry
- https://cordova.apache.org/announcements/2015/05/26/android-402.htmlRelease Notes, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.