Description
We have resolved a security issue in the camera plugin that could have affected certain Cordova (Android) applications. An attacker who could install (or lead the victim to install) a specially crafted (or malicious) Android application would be able to access pictures taken with the app externally.
Remediation
References
http://jvn.jp/en/jp/JVN59779918/index.html
https://cordova.apache.org/news/2020/09/18/camera-plugin-release.html
Related Vulnerabilities
CVE-2020-8124 Vulnerability in maven package org.webjars.npm:url-parse
CVE-2019-10776 Vulnerability in npm package git-diff-apply
CVE-2019-5442 Vulnerability in maven package ro.pippo:pippo-jaxb
CVE-2023-49620 Vulnerability in maven package org.apache.dolphinscheduler:dolphinscheduler-service
CVE-2020-2177 Vulnerability in maven package org.jenkins-ci.plugins:copr