Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CVE-2021-43849

6.2 · MEDIUM
Published Dec 23, 2021 cordova_plugin_fingerprint_all-in-one_project CWE-617 EPSS 0.33% (26th pctl)

Overview

CVE-2021-43849 is a medium-severity vulnerability affecting cordova_plugin_fingerprint_all-in-one_project cordova_plugin_fingerprint_all-in-one. It was published on December 23, 2021 and has a CVSS 3.1 base score of 6.2 (MEDIUM).

This vulnerability has a CVSS 3.1 base score of 6.2, rated MEDIUM. It requires local or adjacent network access to exploit. No authentication or special privileges are required for exploitation.

Technical Description

cordova-plugin-fingerprint-aio is a plugin provides a single and simple interface for accessing fingerprint APIs on both Android 6+ and iOS. In versions prior to 5.0.1 The exported activity `de.niklasmerz.cordova.biometric.BiometricActivity` can cause the app to crash. This vulnerability occurred because the activity didn't handle the case where it is requested with invalid or empty data which results in a crash. Any third party app can constantly call this activity with no permission. A 3rd party app/attacker using event listener can continually stop the app from working and make the victim unable to open it. Version 5.0.1 of the cordova-plugin-fingerprint-aio doesn't export the activity anymore and is no longer vulnerable. If you want to fix older versions change the attribute android:exported in plugin.xml to false. Please upgrade to version 5.0.1 as soon as possible.

Remediation

Check the references section for vendor advisories and patches from cordova_plugin_fingerprint_all-in-one_project. Update cordova_plugin_fingerprint_all-in-one to the latest patched version. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.

Affected Products

Vendor Product Versions Status
cordova_plugin_fingerprint_all-in-one_project cordova_plugin_fingerprint_all-in-one >= 0, < 5.0.1 Affected
google android 6.0 Affected

Frequently Asked Questions

What is CVE-2021-43849?

CVE-2021-43849 is a medium-severity vulnerability affecting cordova_plugin_fingerprint_all-in-one_project cordova_plugin_fingerprint_all-in-one. It was published on December 23, 2021 and has a CVSS 3.1 base score of 6.2 (MEDIUM).

How severe is CVE-2021-43849?

This vulnerability has a CVSS 3.1 base score of 6.2, rated MEDIUM. It requires local or adjacent network access to exploit. No authentication or special privileges are required for exploitation.

How do I fix or remediate CVE-2021-43849?

Check the references section for vendor advisories and patches from cordova_plugin_fingerprint_all-in-one_project. Update cordova_plugin_fingerprint_all-in-one to the latest patched version. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.

How can CyberStrike help with CVE-2021-43849?

CyberStrike's AI-powered security agents can automatically detect CVE-2021-43849 across your infrastructure using autonomous pentesting, DAST scanning, and HackBrowser. The platform continuously monitors for known vulnerabilities and provides actionable remediation guidance prioritized by real-world exploitability.