CVE-2012-6637: Input Validation
Apache Cordova 3.3.0 and earlier and Adobe PhoneGap 2.9.0 and earlier do not anchor the end of domain-name regular expressions, which allows remote attackers to bypass a whitelist protection mechanism via a domain name that contains an acceptable name as an initial substring.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2012-6637?
CVE-2012-6637 has been assigned a medium severity level due to its potential impact on application security.
How does CVE-2012-6637 affect Apache Cordova and Adobe PhoneGap?
CVE-2012-6637 allows remote attackers to bypass a whitelist protection mechanism affecting specific versions of Apache Cordova and Adobe PhoneGap.
How do I fix CVE-2012-6637?
To fix CVE-2012-6637, upgrade to a version of Apache Cordova or Adobe PhoneGap that is later than the affected versions listed.
Which versions of Apache Cordova are vulnerable to CVE-2012-6637?
Apache Cordova versions 3.3.0 and earlier are vulnerable to CVE-2012-6637.
Which versions of Adobe PhoneGap are affected by CVE-2012-6637?
Adobe PhoneGap versions 2.9.0 and earlier are affected by CVE-2012-6637.