Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-gmhc-gw98-7qrj

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Apache Cordova 3.3.0 and earlier and Adobe PhoneGap 2.9.0 and earlier do not anchor the end of domain-name regular expressions, which allows remote attackers to bypass a whitelist protection mechanism via a domain name that contains an acceptable name as an initial substring.

Apache Cordova 3.3.0 and earlier and Adobe PhoneGap 2.9.0 and earlier do not anchor the end of domain-name regular expressions, which allows remote attackers to bypass a whitelist protection mechanism via a domain name that contains an acceptable name as an initial substring.

EPSS

Процентиль: 79%
0.01268
Низкий

Дефекты

CWE-20

Связанные уязвимости

ubuntu
почти 12 лет назад

Apache Cordova 3.3.0 and earlier and Adobe PhoneGap 2.9.0 and earlier do not anchor the end of domain-name regular expressions, which allows remote attackers to bypass a whitelist protection mechanism via a domain name that contains an acceptable name as an initial substring.

nvd
почти 12 лет назад

Apache Cordova 3.3.0 and earlier and Adobe PhoneGap 2.9.0 and earlier do not anchor the end of domain-name regular expressions, which allows remote attackers to bypass a whitelist protection mechanism via a domain name that contains an acceptable name as an initial substring.

EPSS

Процентиль: 79%
0.01268
Низкий

Дефекты

CWE-20