CVE-2015-5256: Medium severity apache cordova vulnerability
Published Nov 23, 2015
·Updated
Apache Cordova-Android before 4.1.0, when an application relies on a remote server, improperly implements a JavaScript whitelist protection mechanism, which allows attackers to bypass intended access restrictions via a crafted URI.
Affected Software
1 affected component
Apache Cordova Android<=3.6.4
Event History
Nov 23, 2015
CVE Published
via MITRE·11:00 AM
Data Sourced
via MITRE·11:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-5256?
CVE-2015-5256 is classified as a medium severity vulnerability.
2
How does CVE-2015-5256 impact applications using Apache Cordova-Android?
CVE-2015-5256 allows attackers to bypass whitelisting protections, potentially compromising the security of applications relying on remote servers.
3
How do I fix CVE-2015-5256?
To mitigate CVE-2015-5256, upgrade to Apache Cordova-Android version 4.1.0 or higher.
4
Which versions of Apache Cordova-Android are affected by CVE-2015-5256?
CVE-2015-5256 affects all versions of Apache Cordova-Android prior to 4.1.0.
5
What is the nature of the vulnerability described in CVE-2015-5256?
CVE-2015-5256 involves improper implementation of a JavaScript whitelist that can be exploited through crafted URIs.