QID 980772
QID 980772: Nodejs (npm) Security Update for cordova-plugin-ionic-webview (GHSA-xwjh-cp99-cj8q)
Versions of `cordova-plugin-ionic-webview` prior to 2.2.0 are vulnerable to Path Traversal, allowing attackers access to OS local files that should be inaccessible by third-party applications. The package launches a webserver listening on http://localhost:8080 without restricting access of the app itself, thus escaping the iOS application sandbox and accessing local files.
## Recommendation
Upgrade to version 2.2.0
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-xwjh-cp99-cj8q for updates pertaining to this vulnerability.
Vendor References
- GHSA-xwjh-cp99-cj8q -
github.com/advisories/GHSA-xwjh-cp99-cj8q
CVEs related to QID 980772
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-xwjh-cp99-cj8q | cordova-plugin-ionic-webview |
|