apache cordova-inappbrowser CVE-2019-0219 in Apache and Oracle Products
Published on January 14, 2020

product logo product logo
A website running in the InAppBrowser webview on Android could execute arbitrary JavaScript in the main application's webview using a specially crafted gap-iab: URI.

NVD


Products Associated with CVE-2019-0219

You can be notified by email with stack.watch whenever vulnerabilities like CVE-2019-0219 are published in these products:

 
 
 

Affected Versions

Apache Cordova Version Cordova Android applications using the InAppBrowser plugin ( cordova-plugin-inappbrowser version 3.0.0 and below ) is affected by CVE-2019-0219

Exploit Probability

EPSS
8.91%
Percentile
92.41%

EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.