QID 995817
Date Published: 2023-11-06
QID 995817: NodeJs (Npm) Security Update for cordova-plugin-fingerprint-aio (GHSA-7vfx-hfvm-rhr8)
Sending a specially crafted intent with an invalid/empty extras de.niklasmerz.cordova.biometric.BiometricActivity can cause the app to crash. sending the intent repeatedly can prevent the app using this plugin from working, resulting in a denial of service (DoS) condition.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-7vfx-hfvm-rhr8 for updates and patch information.
Vendor References
- GHSA-7vfx-hfvm-rhr8 -
github.com/advisories/GHSA-7vfx-hfvm-rhr8
CVEs related to QID 995817
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-7vfx-hfvm-rhr8 | cordova-plugin-fingerprint-aio |
|