Severity
7.5HIGH
EPSS
1.9%
top 16.97%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 3
Latest updateMay 17

Description

Apache Cordova 3.3.0 and earlier and Adobe PhoneGap 2.9.0 and earlier allow remote attackers to bypass intended device-resource restrictions of an event-based bridge via a crafted library clone that leverages IFRAME script execution and waits a certain amount of time for an OnJsPrompt handler return value as an alternative to correct synchronization.

CVSS vector

AV:N/AC:L/C:P/I:P/A:PExploitability: 10.0 | Impact: 6.4

Affected Packages2 packages

NVDadobe/phonegap2.9.0+11
NVDapache/cordova3.3.0+4

Patches

🔴Vulnerability Details

4
GHSA
GHSA-qjxm-w9fw-977v: Apache Cordova 32022-05-17
GHSA
OpenStack Glance Denial of service by creating a large number of images2022-05-17
GHSA
OpenStack Glance Denial of service by creating a large number of images2022-05-17
CVEList
CVE-2014-1881: Apache Cordova 32014-03-03

📋Vendor Advisories

2
Red Hat
openstack-glance: potential resource exhaustion and denial of service using images manipulation API2015-02-19
Red Hat
openstack-glance: potential resource exhaustion and denial of service using images manipulation API2015-02-19

💬Community

1
Bugzilla
CVE-2014-9684 CVE-2015-1881 openstack-glance: potential resource exhaustion and denial of service using images manipulation API2015-02-20
CVE-2014-1881 (HIGH CVSS 7.5) | Apache Cordova 3.3.0 and earlier an | cvebase.io