Back to search
CVE-2015-5256
Published: Nov 23, 2015
Modified: Aug 6, 2024
PUBLISHED
Description
Apache Cordova-Android before 4.1.0, when an application relies on a remote server, improperly implements a JavaScript whitelist protection mechanism, which allows attackers to bypass intended access restrictions via a crafted URI.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
20151120 Fwd: CVE-2015-5256: Apache Cordova vulnerable to improper application of whitelist restrictions
mailing-list
x_refsource_BUGTRAQ
JVNDB-2015-000187
third-party-advisory
x_refsource_JVNDB
77677
vdb-entry
x_refsource_BID
https://cordova.apache.org/announcements/2015/11/20/security.html
x_refsource_CONFIRM
JVN#18889193
third-party-advisory
x_refsource_JVN
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now