CVE-2019-0219 in Apache and Oracle Products
Published on January 14, 2020
A website running in the InAppBrowser webview on Android could execute arbitrary JavaScript in the main application's webview using a specially crafted gap-iab: URI.
Products Associated with CVE-2019-0219
You can be notified by email with stack.watch whenever vulnerabilities like CVE-2019-0219 are published in these products:
Affected Versions
Apache Cordova Version Cordova Android applications using the InAppBrowser plugin ( cordova-plugin-inappbrowser version 3.0.0 and below ) is affected by CVE-2019-0219Exploit Probability
EPSS
8.91%
Percentile
92.41%
EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.