Description
CRLF injection vulnerability in the Apache Cordova File Transfer Plugin (cordova-plugin-file-transfer) for Android before 1.3.0 allows remote attackers to inject arbitrary headers via CRLF sequences in the filename of an uploaded file.
Remediation
References
http://www.securityfocus.com/bid/76832
https://cordova.apache.org/news/2015/09/21/file-transfer-release.html
Related Vulnerabilities
CVE-2020-2208 Vulnerability in maven package org.jenkins-ci.plugins:slack-uploader
CVE-2020-2238 Vulnerability in maven package org.jenkins-ci.plugins:git-parameter
CVE-2023-24998 Vulnerability in maven package commons-fileupload:commons-fileupload
CVE-2011-3190 Vulnerability in maven package org.apache.tomcat:tomcat-coyote
CVE-2018-1000600 Vulnerability in maven package com.coravy.hudson.plugins.github:github