CVE-2018-16202: Path Traversal
Published Jan 9, 2019
·Updated
Directory traversal vulnerability in cordova-plugin-ionic-webview versions prior to 2.2.0 (not including 2.0.0-beta.0, 2.0.0-beta.1, 2.0.0-beta.2, and 2.1.0-0) allows remote attackers to access arbitrary files via unspecified vectors.
Affected Software
4 affected componentsFixes available
GE Gas Power ToolBoxST OSC<07.09.07
07.09.07
Ionicframework Ionic Web View Cordova<=1.2.1
Ionicframework Ionic Web View Cordova>=2.0.1<2.2.0
Ionicframework Ionic Web View Cordova=2.0.0
Event History
Jan 9, 2019
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2018-16202?
CVE-2018-16202 is classified as a medium severity vulnerability.
2
How do I fix CVE-2018-16202?
To fix CVE-2018-16202, upgrade cordova-plugin-ionic-webview to version 2.2.0 or later.
3
What types of attacks can CVE-2018-16202 facilitate?
CVE-2018-16202 can facilitate unauthorized access to arbitrary files by remote attackers.
4
Which versions of cordova-plugin-ionic-webview are affected by CVE-2018-16202?
CVE-2018-16202 affects cordova-plugin-ionic-webview versions prior to 2.2.0, except for 2.0.0-beta.0, 2.0.0-beta.1, 2.0.0-beta.2, and 2.1.0-0.
5
What is the main cause of CVE-2018-16202?
The main cause of CVE-2018-16202 is a directory traversal vulnerability in the affected versions of the plugin.