First published: Mon Mar 03 2014(Updated: )
Apache Cordova 3.3.0 and earlier and Adobe PhoneGap 2.9.0 and earlier do not anchor the end of domain-name regular expressions, which allows remote attackers to bypass a whitelist protection mechanism via a domain name that contains an acceptable name as an initial substring.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apache Cordova | <=3.3.0 | |
Apache Cordova | =3.0.0 | |
Apache Cordova | =3.0.0-rc1 | |
Apache Cordova | =3.1.0 | |
Apache Cordova | =3.1.0-rc1 | |
Apache Cordova | =3.2.0 | |
Apache Cordova | =3.2.0-rc1 | |
Apache Cordova | =3.3.0-rc1 | |
Adobe PhoneGap | <=2.9.0 | |
Adobe PhoneGap | =2.0.0 | |
Adobe PhoneGap | =2.0.0-rc1 | |
Adobe PhoneGap | =2.1.0 | |
Adobe PhoneGap | =2.2.0 | |
Adobe PhoneGap | =2.2.0-rc1 | |
Adobe PhoneGap | =2.2.0-rc2 | |
Adobe PhoneGap | =2.3.0 | |
Adobe PhoneGap | =2.3.0-rc1 | |
Adobe PhoneGap | =2.3.0-rc2 | |
Adobe PhoneGap | =2.4.0 | |
Adobe PhoneGap | =2.4.0-rc1 | |
Adobe PhoneGap | =2.5.0 | |
Adobe PhoneGap | =2.5.0-rc1 | |
Adobe PhoneGap | =2.6.0 | |
Adobe PhoneGap | =2.6.0-rc1 | |
Adobe PhoneGap | =2.7.0 | |
Adobe PhoneGap | =2.7.0-rc1 | |
Adobe PhoneGap | =2.8.0 | |
Adobe PhoneGap | =2.8.1 | |
Adobe PhoneGap | =2.9.0-rc1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-6637 has been assigned a medium severity level due to its potential impact on application security.
CVE-2012-6637 allows remote attackers to bypass a whitelist protection mechanism affecting specific versions of Apache Cordova and Adobe PhoneGap.
To fix CVE-2012-6637, upgrade to a version of Apache Cordova or Adobe PhoneGap that is later than the affected versions listed.
Apache Cordova versions 3.3.0 and earlier are vulnerable to CVE-2012-6637.
Adobe PhoneGap versions 2.9.0 and earlier are affected by CVE-2012-6637.