CVE-2020-11990: Low severity apache cordova vulnerability
Published Dec 1, 2020
·Updated
We have resolved a security issue in the camera plugin that could have affected certain Cordova (Android) applications. An attacker who could install (or lead the victim to install) a specially crafted (or malicious) Android application would be able to access pictures taken with the app externally.
Affected Software
1 affected component
Apache Cordova Android=4.1.0
Event History
Dec 1, 2020
CVE Published
via MITRE·04:46 PM
Data Sourced
via MITRE·04:46 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2020-11990?
CVE-2020-11990 has been classified as a medium severity vulnerability.
2
How do I fix CVE-2020-11990?
To fix CVE-2020-11990, upgrade the Apache Cordova camera plugin to the latest version.
3
Who is affected by CVE-2020-11990?
CVE-2020-11990 affects applications built with Apache Cordova version 4.1.0 for Android.
4
What type of attack does CVE-2020-11990 enable?
CVE-2020-11990 allows an attacker to access pictures taken by the app if they can convince the user to install a malicious application.
5
When was CVE-2020-11990 disclosed?
CVE-2020-11990 was disclosed on September 18, 2020.