CVE-2021-43849
Summary
| CVE | CVE-2021-43849 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-12-23 17:15:00 UTC |
| Updated | 2022-01-11 17:39:00 UTC |
| Description | cordova-plugin-fingerprint-aio is a plugin provides a single and simple interface for accessing fingerprint APIs on both Android 6+ and iOS. In versions prior to 5.0.1 The exported activity `de.niklasmerz.cordova.biometric.BiometricActivity` can cause the app to crash. This vulnerability occurred because the activity didn't handle the case where it is requested with invalid or empty data which results in a crash. Any third party app can constantly call this activity with no permission. A 3rd party app/attacker using event listener can continually stop the app from working and make the victim unable to open it. Version 5.0.1 of the cordova-plugin-fingerprint-aio doesn't export the activity anymore and is no longer vulnerable. If you want to fix older versions change the attribute android:exported in plugin.xml to false. Please upgrade to version 5.0.1 as soon as possible. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| Update Fingerprint.swift · NiklasMerz/cordova-plugin-fingerprint-aio@27434a2 · GitHub |
MISC |
github.com |
|
| Denial of service (DoS) vulnerability on Android · Advisory · NiklasMerz/cordova-plugin-fingerprint-aio · GitHub |
CONFIRM |
github.com |
|
| Release v5.0.1 · NiklasMerz/cordova-plugin-fingerprint-aio · GitHub |
MISC |
github.com |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 995817 NodeJs (Npm) Security Update for cordova-plugin-fingerprint-aio (GHSA-7vfx-hfvm-rhr8)