CVE-2014-1881: High severity Apache Cordova vulnerability
Apache Cordova 3.3.0 and earlier and Adobe PhoneGap 2.9.0 and earlier allow remote attackers to bypass intended device-resource restrictions of an event-based bridge via a crafted library clone that leverages IFRAME script execution and waits a certain amount of time for an OnJsPrompt handler return value as an alternative to correct synchronization.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-1881?
CVE-2014-1881 is considered a critical vulnerability due to its potential for remote exploitation.
How do I fix CVE-2014-1881?
To fix CVE-2014-1881, upgrade Apache Cordova to version 3.4.0 or later, or Adobe PhoneGap to version 3.0.0 or later.
What software is affected by CVE-2014-1881?
CVE-2014-1881 affects Apache Cordova versions 3.3.0 and earlier as well as Adobe PhoneGap versions 2.9.0 and earlier.
What type of attack can exploit CVE-2014-1881?
CVE-2014-1881 can be exploited through crafted library clones that leverage IFRAME script execution to bypass device-resource restrictions.
How can I mitigate risks associated with CVE-2014-1881?
Mitigation for CVE-2014-1881 involves applying the latest security patches and restricting the use of IFRAMEs where possible.