CVE Vulnerabilities

CVE-2014-1883

Published: Mar 03, 2014 | Modified: Apr 12, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Adobe PhoneGap before 2.6.0 on Android uses the shouldOverrideUrlLoading callback instead of the proper shouldInterceptRequest callback, which allows remote attackers to bypass intended device-resource restrictions via content that is accessed (1) in an IFRAME element or (2) with the XMLHttpRequest method by a crafted application.

Affected Software

NameVendorStart VersionEnd Version
PhonegapAdobe*2.5.0 (including)
PhonegapAdobe2.0.0 (including)2.0.0 (including)
PhonegapAdobe2.0.0-rc1 (including)2.0.0-rc1 (including)
PhonegapAdobe2.1.0 (including)2.1.0 (including)
PhonegapAdobe2.2.0 (including)2.2.0 (including)
PhonegapAdobe2.2.0-rc1 (including)2.2.0-rc1 (including)
PhonegapAdobe2.2.0-rc2 (including)2.2.0-rc2 (including)
PhonegapAdobe2.3.0 (including)2.3.0 (including)
PhonegapAdobe2.3.0-rc1 (including)2.3.0-rc1 (including)
PhonegapAdobe2.3.0-rc2 (including)2.3.0-rc2 (including)
PhonegapAdobe2.4.0 (including)2.4.0 (including)
PhonegapAdobe2.4.0-rc1 (including)2.4.0-rc1 (including)
PhonegapAdobe2.5.0-rc1 (including)2.5.0-rc1 (including)
Cordova-ubuntuUbuntusaucy*
Cordova-ubuntuUbuntutrusty*
Cordova-ubuntuUbuntuutopic*
Cordova-ubuntuUbuntuvivid*
Cordova-ubuntuUbuntuwily*
Cordova-ubuntu-3.4Ubuntuartful*
Cordova-ubuntu-3.4Ubuntutrusty*
Cordova-ubuntu-3.4Ubuntuutopic*
Cordova-ubuntu-3.4Ubuntuvivid*
Cordova-ubuntu-3.4Ubuntuwily*
Cordova-ubuntu-3.4Ubuntuxenial*
Cordova-ubuntu-3.4Ubuntuyakkety*
Cordova-ubuntu-3.4Ubuntuzesty*

References