原始 OSV JSON{
"id": "GHSA-36j3-xxf7-4pqg",
"aliases": [
"CVE-2020-6506"
],
"details": "A universal cross-site scripting (UXSS) vulnerability, CVE-2020-6506 (https://crbug.com/1083819), has been identified in the Android WebView system component, which allows cross-origin iframes to execute arbitrary JavaScript in the top-level document. This vulnerability affects React Native apps which use a `react-native-webview` that allows navigation to arbitrary URLs, and when that app runs on systems with an Android WebView version prior to 83.0.4103.106.\n\n## Pending mitigation\n\nEnsure users update their Android WebView system component via the Google Play Store to 83.0.4103.106 or higher to avoid this UXSS. 'react-native-webview' is working on a mitigation but it could take some time.\n\n### References\n\nhttps://alesandroortiz.com/articles/uxss-android-webview-cve-2020-6506/\n\n",
"summary": "Android WebView Universal Cross-site Scripting",
"affected": [
{
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "0"
},
{
"fixed": "11.0.0"
}
]
}
],
"package": {
"name": "react-native-webview",
"ecosystem": "npm"
},
"database_specific": {
"last_known_affected_version_range": "<= 10.10.2"
}
}
],
"modified": "2022-08-03T23:40:07Z",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N"
}
],
"published": "2020-10-02T16:22:41Z",
"references": [
{
"url": "https://github.com/react-native-community/react-native-webview/security/advisories/GHSA-36j3-xxf7-4pqg",
"type": "WEB"
},
{
"url": "https://github.com/react-native-webview/react-native-webview/security/advisories/GHSA-36j3-xxf7-4pqg",
"type": "WEB"
},
{
"url": "https://nvd.nist.gov/vuln/detail/CVE-2020-6506",
"type": "ADVISORY"
},
{
"url": "https://github.com/react-native-webview/react-native-webview/pull/1747",
"type": "WEB"
},
{
"url": "https://www.npmjs.com/advisories/1560",
"type": "WEB"
},
{
"url": "https://security.gentoo.org/glsa/202101-30",
"type": "WEB"
},
{
"url": "https://security.gentoo.org/glsa/202007-08",
"type": "WEB"
},
{
"url": "https://lists.apache.org/thread.html/rf082834ad237f78a63671aec0cef8874f9232b7614529cc3d3e304c5@%3Ccommits.cordova.apache.org%3E",
"type": "WEB"
},
{
"url": "https://lists.apache.org/thread.html/rc81e12fc9287f8743d59099b1af40f968f1cfec9eac98a63c2c62c69@%3Cissues.cordova.apache.org%3E",
"type": "WEB"
},
{
"url": "https://lists.apache.org/thread.html/rc0ebe639927fa09e222aa56bf5ad6e700218f334ecc6ba9da4397728@%3Cissues.cordova.apache.org%3E",
"type": "WEB"
},
{
"url": "https://lists.apache.org/thread.html/ra58733fbb88d5c513b3f14a14850083d506b9129103e0ab433c3f680@%3Cissues.cordova.apache.org%3E",
"type": "WEB"
},
{
"url": "https://lists.apache.org/thread.html/r2769c33da7f7ece7e4e31837c1e1839d6657c7c13bb8d228670b8da0@%3Cissues.cordova.apache.org%3E",
"type": "WEB"
},
{
"url": "https://lists.apache.org/thread.html/r1eadf38b38ee20405811958c8a01f78d6b28e058c84c9fa6c1a8663d@%3Cissues.cordova.apache.org%3E",
"type": "WEB"
},
{
"url": "https://lists.apache.org/thread.html/r1ab80f8591d5c2147898076e3945dad1c897513630aabec556883275@%3Cissues.cordova.apache.org%3E",
"type": "WEB"
},
{
"url": "https://github.com/react-native-webview/react-native-webview/releases/tag/v11.0.0",
"type": "WEB"
},
{
"url": "https://github.com/react-native-community/react-native-webview",
"type": "PACKAGE"
},
{
"url": "https://crbug.com/1083819",
"type": "WEB"
},
{
"url": "https://chromereleases.googleblog.com/2020/06/stable-channel-update-for-desktop_15.html",
"type": "WEB"
},
{
"url": "https://alesandroortiz.com/articles/uxss-android-webview-cve-2020-6506",
"type": "WEB"
}
],
"schema_version": "1.4.0",
"database_specific": {
"cwe_ids": [
"CWE-79",
"CWE-863"
],
"severity": "MODERATE",
"github_reviewed": true,
"nvd_published_at": "2020-07-22T17:15:00Z",
"github_reviewed_at": "2020-10-02T16:22:01Z"
}
}