Configuration Vulnerability in Apache Cordova for Android Applications
CVE-2015-1835

5.3MEDIUM

Key Information:

Vendor
Apache
Status
Vendor
CVE Published:
27 October 2017

Summary

The vulnerability affects Apache Cordova for Android applications prior to versions 3.7.2 and 4.0.2. In instances where applications fail to define explicit values within the config.xml file, malicious actors can exploit undefined secondary configuration variables. This is achieved via specially crafted intent URLs, allowing potential alterations to application behavior without user consent. It is crucial for developers to ensure proper configuration to safeguard their applications from unauthorized modifications.

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.