CVE-2019-0219
published 2020-01-14CVE-2019-0219: A website running in the InAppBrowser webview on Android could execute arbitrary JavaScript in the main application's webview using a specially crafted…
PriorityP355critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
7.83%
94.0th percentile
A website running in the InAppBrowser webview on Android could execute arbitrary JavaScript in the main application's webview using a specially crafted gap-iab: URI.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | cordova | — | — |
| apache | cordova_inappbrowser | <= 3.0.0 | — |
| oracle | instantis_enterprisetrack | — | — |
| oracle | instantis_enterprisetrack | — | — |
| oracle | instantis_enterprisetrack | — | — |
| oracle | retail_xstore_point_of_service | — | — |
| oracle | retail_xstore_point_of_service | — | — |
| oracle | retail_xstore_point_of_service | — | — |
| oracle | retail_xstore_point_of_service | — | — |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
vendor_oracle9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Oracle
Oracle Oracle Supply Chain Risk Matrix: Mobile Applications (Apache cordova-plugin-inappbrowser) — CVE-2019-0219
vendor_oracle·2022-07-15·CVSS 9.8
CVE-2019-0219 [CRITICAL] Oracle Oracle Supply Chain Risk Matrix: Mobile Applications (Apache cordova-plugin-inappbrowser) — CVE-2019-0219
Oracle Oracle Supply Chain Risk Matrix: Mobile Applications (Apache cordova-plugin-inappbrowser) vulnerability
CVE: CVE-2019-0219
CVSS: 9.8
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujul2022 (JUL 2022)
Oracle
Oracle Oracle Retail Applications Risk Matrix: Xenvironment (Apache cordova-plugin-inappbrowser) — CVE-2019-0219
vendor_oracle·2021-07-15·CVSS 9.8
CVE-2019-0219 [CRITICAL] Oracle Oracle Retail Applications Risk Matrix: Xenvironment (Apache cordova-plugin-inappbrowser) — CVE-2019-0219
Oracle Oracle Retail Applications Risk Matrix: Xenvironment (Apache cordova-plugin-inappbrowser) vulnerability
CVE: CVE-2019-0219
CVSS: 9.8
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujul2021 (JUL 2021)
Oracle
Oracle Oracle Construction and Engineering Risk Matrix: Browser (Apache Cordova InAppBrowser) — CVE-2019-0219
vendor_oracle·2021-04-15·CVSS 9.8
CVE-2019-0219 [CRITICAL] Oracle Oracle Construction and Engineering Risk Matrix: Browser (Apache Cordova InAppBrowser) — CVE-2019-0219
Oracle Oracle Construction and Engineering Risk Matrix: Browser (Apache Cordova InAppBrowser) vulnerability
CVE: CVE-2019-0219
CVSS: 9.8
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuapr2021 (APR 2021)
OSV
Privilege Escalation in cordova-plugin-inappbrowser
osv·2020-09-04
CVE-2019-0219 [CRITICAL] Privilege Escalation in cordova-plugin-inappbrowser
Privilege Escalation in cordova-plugin-inappbrowser
Versions of `cordova-plugin-inappbrowser` prior to 3.1.0 are vulnerable to Privilege Escalation. A website running in the InAppBrowser webview on Android could execute arbitrary JavaScript in the main application's webview using a specially crafted gap-iab: URI. This affects Cordova Android applications using the package.
## Recommendation
Upgrade to version 3.1.0 or later.
GHSA
Privilege Escalation in cordova-plugin-inappbrowser
ghsa·2020-09-04
CVE-2019-0219 [CRITICAL] CWE-79 Privilege Escalation in cordova-plugin-inappbrowser
Privilege Escalation in cordova-plugin-inappbrowser
Versions of `cordova-plugin-inappbrowser` prior to 3.1.0 are vulnerable to Privilege Escalation. A website running in the InAppBrowser webview on Android could execute arbitrary JavaScript in the main application's webview using a specially crafted gap-iab: URI. This affects Cordova Android applications using the package.
## Recommendation
Upgrade to version 3.1.0 or later.
No detection rules found.
No public exploits indexed.
http://www.openwall.com/lists/oss-security/2019/11/28/1https://lists.apache.org/thread.html/197482d5ab80c0bff4a5ec16e1b0466df38389d9a4b5331d777f14fc%40%3Cdev.cordova.apache.org%3Ehttps://lists.apache.org/thread/4vtg0trdrh5203dktt4f3vkd5z2d5ndjhttps://www.oracle.com//security-alerts/cpujul2021.htmlhttps://www.oracle.com/security-alerts/cpuApr2021.htmlhttps://www.oracle.com/security-alerts/cpujul2022.htmlhttp://www.openwall.com/lists/oss-security/2019/11/28/1https://lists.apache.org/thread.html/197482d5ab80c0bff4a5ec16e1b0466df38389d9a4b5331d777f14fc%40%3Cdev.cordova.apache.org%3Ehttps://lists.apache.org/thread/4vtg0trdrh5203dktt4f3vkd5z2d5ndjhttps://www.oracle.com//security-alerts/cpujul2021.htmlhttps://www.oracle.com/security-alerts/cpuApr2021.htmlhttps://www.oracle.com/security-alerts/cpujul2022.html
2020-01-14
Published