Domain Name Bypass Vulnerability in Apache Cordova and Adobe PhoneGap
CVE-2012-6637
Currently unrated
Summary
Apache Cordova versions up to 3.3.0 and Adobe PhoneGap versions up to 2.9.0 are susceptible to a vulnerability where the regular expressions used for domain-name filtering do not properly anchor at the end. This flaw allows remote attackers to exploit the whitelist protection mechanism by using a specially crafted domain name that contains an accepted name as a prefix. Consequently, unauthorized access may be gained, leading to potential exploitation in mobile applications built on these platforms.
References
Timeline
Vulnerability published
Vulnerability Reserved