Apache Cordova iOS before 4.0.0 might allow attackers to bypass a URL whitelist protection mechanism in an app and load arbitrary resources by leveraging unspecified methods.
Software security is not security software. Here we're concerned with topics like authentication, access control, confidentiality, cryptography, and privilege management.
Link | Tags |
---|---|
http://packetstormsecurity.com/files/136840/Apache-Cordova-iOS-3.9.1-Access-Bypass.html | |
https://cordova.apache.org/announcements/2016/04/27/security.html | vendor advisory |
http://jvndb.jvn.jp/en/contents/2016/JVNDB-2016-000058.html | third party advisory |
http://www.securityfocus.com/archive/1/538211/100/0/threaded | mailing list |
http://www.securityfocus.com/bid/88764 | vdb entry |
http://jvn.jp/en/jp/JVN35341085/index.html | third party advisory |