CVE-2014-1884: High severity Apache Cordova vulnerability
Apache Cordova 3.3.0 and earlier and Adobe PhoneGap 2.9.0 and earlier on Windows Phone 7 and 8 do not properly restrict navigation events, which allows remote attackers to bypass intended device-resource restrictions via content that is accessed (1) in an IFRAME element or (2) with the XMLHttpRequest method by a crafted application.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-1884?
CVE-2014-1884 is classified as a medium severity vulnerability.
How do I fix CVE-2014-1884?
To fix CVE-2014-1884, upgrade Apache Cordova to version 3.4.0 or later and Adobe PhoneGap to version 2.9.1 or later.
Which versions are affected by CVE-2014-1884?
CVE-2014-1884 affects Apache Cordova versions up to and including 3.3.0 and Adobe PhoneGap versions up to and including 2.9.0.
What type of attacks are possible with CVE-2014-1884?
CVE-2014-1884 allows remote attackers to bypass device-resource restrictions via IFRAME or XMLHttpRequest.
Is CVE-2014-1884 specific to any platforms?
Yes, CVE-2014-1884 specifically affects Windows Phone 7 and 8.