Description
CRLF injection vulnerability in the Apache Cordova File Transfer Plugin (cordova-plugin-file-transfer) for Android before 1.3.0 allows remote attackers to inject arbitrary headers via CRLF sequences in the filename of an uploaded file.
Remediation
References
http://www.securityfocus.com/bid/76832
https://cordova.apache.org/news/2015/09/21/file-transfer-release.html
Related Vulnerabilities
CVE-2020-17523 Vulnerability in maven package org.apache.shiro:shiro-web
CVE-2020-1933 Vulnerability in maven package org.apache.nifi:nifi-web-api
CVE-2022-24697 Vulnerability in maven package org.apache.kylin:kylin-spark-engine
CVE-2020-1695 Vulnerability in maven package org.jboss.resteasy:resteasy-jaxrs
CVE-2023-35926 Vulnerability in npm package @backstage/plugin-scaffolder-backend