Path Traversal in cordova-plugin-ionic-webview
High severity
GitHub Reviewed
Published
Feb 12, 2019
to the GitHub Advisory Database
•
Updated Jan 9, 2023
Description
Published to the GitHub Advisory Database
Feb 12, 2019
Reviewed
Jun 16, 2020
Last updated
Jan 9, 2023
Versions of
cordova-plugin-ionic-webview
prior to 2.2.0 are vulnerable to Path Traversal, allowing attackers access to OS local files that should be inaccessible by third-party applications. The package launches a webserver listening on http://localhost:8080 without restricting access of the app itself, thus escaping the iOS application sandbox and accessing local files.Recommendation
Upgrade to version 2.2.0
References