CVE-2014-1882: High severity Adobe PhoneGap vulnerability
Apache Cordova 3.3.0 and earlier and Adobe PhoneGap 2.9.0 and earlier allow remote attackers to bypass intended device-resource restrictions of an event-based bridge via a crafted library clone that leverages IFRAME script execution and directly accesses bridge JavaScript objects, as demonstrated by certain cordova.require calls.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-1882?
CVE-2014-1882 is classified as a high-severity vulnerability due to its potential to allow unauthorized access to device resources.
How do I fix CVE-2014-1882?
To remediate CVE-2014-1882, upgrade to a version of Apache Cordova newer than 3.3.0 or Adobe PhoneGap newer than 2.9.0.
What type of vulnerability is CVE-2014-1882?
CVE-2014-1882 is a remote code execution vulnerability that allows for bypassing device-resource restrictions.
Which versions of Adobe PhoneGap are affected by CVE-2014-1882?
Adobe PhoneGap versions 2.9.0 and earlier are affected by CVE-2014-1882.
Which versions of Apache Cordova are impacted by CVE-2014-1882?
Apache Cordova versions 3.3.0 and earlier are vulnerable to CVE-2014-1882.