Apache Cordova Android before 3.5.1 allows remote attackers to bypass the HTTP whitelist and connect to arbitrary servers by using JavaScript to open WebSocket connections through WebView.
References
Configurations
History
No history.
Information
Published : 2014-11-15 21:59
Updated : 2025-04-12 10:46
NVD link : CVE-2014-3501
Mitre link : CVE-2014-3501
CVE.ORG link : CVE-2014-3501
JSON object : View
Products Affected
apache
- cordova
CWE
CWE-254
7PK - Security Features