Vulnerability Description
We have resolved a security issue in the camera plugin that could have affected certain Cordova (Android) applications. An attacker who could install (or lead the victim to install) a specially crafted (or malicious) Android application would be able to access pictures taken with the app externally.
CVSS Score
LOW
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Apache | Cordova | 4.1.0 |
References
- http://jvn.jp/en/jp/JVN59779918/index.htmlThird Party Advisory
- https://cordova.apache.org/news/2020/09/18/camera-plugin-release.htmlRelease NotesVendor Advisory
- http://jvn.jp/en/jp/JVN59779918/index.htmlThird Party Advisory
- https://cordova.apache.org/news/2020/09/18/camera-plugin-release.htmlRelease NotesVendor Advisory
FAQ
What is CVE-2020-11990?
CVE-2020-11990 is a vulnerability with a CVSS score of 3.3 (LOW). We have resolved a security issue in the camera plugin that could have affected certain Cordova (Android) applications. An attacker who could install (or lead the victim to install) a specially crafte...
How severe is CVE-2020-11990?
CVE-2020-11990 has been rated LOW with a CVSS base score of 3.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-11990?
Check the references section above for vendor advisories and patch information. Affected products include: Apache Cordova.