First published: Wed Jan 09 2019(Updated: )
Directory traversal vulnerability in cordova-plugin-ionic-webview versions prior to 2.2.0 (not including 2.0.0-beta.0, 2.0.0-beta.1, 2.0.0-beta.2, and 2.1.0-0) allows remote attackers to access arbitrary files via unspecified vectors.
Credit: vultures@jpcert.or.jp
Affected Software | Affected Version | How to fix |
---|---|---|
GE Gas Power ToolBoxST OSC | <07.09.07 | 07.09.07 |
Ionic Framework | <=1.2.1 | |
Ionic Framework | >=2.0.1<2.2.0 | |
Ionic Framework | =2.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-16202 is classified as a medium severity vulnerability.
To fix CVE-2018-16202, upgrade cordova-plugin-ionic-webview to version 2.2.0 or later.
CVE-2018-16202 can facilitate unauthorized access to arbitrary files by remote attackers.
CVE-2018-16202 affects cordova-plugin-ionic-webview versions prior to 2.2.0, except for 2.0.0-beta.0, 2.0.0-beta.1, 2.0.0-beta.2, and 2.1.0-0.
The main cause of CVE-2018-16202 is a directory traversal vulnerability in the affected versions of the plugin.