24. 24
Cordovaにvする巌樋來の鷂
CVE-2015-5208
Apache Cordova iOS before 4.0.0 allows remote attackers to execute arbitrary plugins via a link.
CVE-2015-5207
Apache Cordova iOS before 4.0.0 might allow attackers to bypass a URL whitelist protection mechanism in an app and load
arbitrary resources by leveraging unspecified methods.
CVE-2015-5204
CRLF injection vulnerability in the Apache Cordova File Transfer Plugin (cordova-plugin-file-transfer) for Android before
1.3.0 allows remote attackers to inject arbitrary headers via CRLF sequences in the filename of an uploaded file.
CVE-2015-8320
Apache Cordova-Android before 3.7.0 improperly generates random values for BridgeSecret data, which makes it easier for
attackers to conduct bridge hijacking attacks by predicting a value.
CVE-2015-5256
Apache Cordova-Android before 4.1.0, when an application relies on a remote server, improperly implements a JavaScript
whitelist protection mechanism, which allows attackers to bypass intended access restrictions via a crafted URI.
Cordova/プラグインの巌樋來
25. 25
Google Play Storeでの
巌樋來のあるCordovaが喘いられている栽、Google Play Storeにて巷_唯
峭が佩われる。
Google Play Storeでのh苧並
https://support.google.com/faqs/answer/6325474?hl=ja
F壓はCordova Android 4.1.1參念で恬られ
たパッケ`ジはアップロ`ド音辛。
Cordovaの巌樋來がk伏すると書瘁も
が駅勣になる。メンテナンス悶崙を屁えて
おく駅勣がある。
Cordova/プラグインの巌樋來