ios/CDVFileTransfer.m in the Apache Cordova File-Transfer standalone plugin (org.apache.cordova.file-transfer) before 0.4.2 for iOS and the File-Transfer plugin for iOS from Cordova 2.4.0 through 2.9.0 might allow remote attackers to spoof SSL servers by leveraging a default value of true for the trustAllHosts option.
References
Configurations
History
No history.
Information
Published : 2017-10-30 19:29
Updated : 2025-04-20 01:37
NVD link : CVE-2014-0072
Mitre link : CVE-2014-0072
CVE.ORG link : CVE-2014-0072
JSON object : View
Products Affected
apache
- cordova_file_transfer
- cordova
CWE
CWE-20
Improper Input Validation