CVE-2014-3500: Medium severity apache cordova vulnerability
Published Nov 15, 2014
·Updated
Apache Cordova Android before 3.5.1 allows remote attackers to change the start page via a crafted intent URL.
Affected Software
1 affected component
Apache Cordova Android<=3.5.0
Event History
Nov 15, 2014
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-3500?
CVE-2014-3500 is classified as a medium severity vulnerability.
2
How do I fix CVE-2014-3500?
To fix CVE-2014-3500, upgrade Apache Cordova Android to version 3.5.1 or later.
3
What type of attack does CVE-2014-3500 allow?
CVE-2014-3500 allows remote attackers to alter the start page through a crafted intent URL.
4
Which versions of Apache Cordova Android are affected by CVE-2014-3500?
CVE-2014-3500 affects Apache Cordova Android versions up to and including 3.5.0.
5
Is CVE-2014-3500 easy to exploit?
CVE-2014-3500 can be exploited remotely, making it a significant risk if the software is not updated.