Description
We have resolved a security issue in the camera plugin that could have affected certain Cordova (Android) applications. An attacker who could install (or lead the victim to install) a specially crafted (or malicious) Android application would be able to access pictures taken with the app externally.
Remediation
References
http://jvn.jp/en/jp/JVN59779918/index.html
https://cordova.apache.org/news/2020/09/18/camera-plugin-release.html
Related Vulnerabilities
CVE-2019-10370 Vulnerability in maven package org.jenkins-ci.plugins:mask-passwords
CVE-2020-14967 Vulnerability in maven package org.webjars.npm:jsrsasign
CVE-2023-30517 Vulnerability in maven package io.jenkins.plugins:neuvector-vulnerability-scanner
CVE-2021-41183 Vulnerability in maven package org.webjars.bowergithub.jquery:jquery-ui
CVE-2019-1010266 Vulnerability in maven package org.webjars.bower:lodash