• Menu
  • Skip to main content
  • Skip to primary sidebar

The Cyber Security News

Latest Cyber Security News

Header Right

  • Latest News
  • Vulnerabilities
  • Cloud Services
apache cordova app harness targeted in dependency confusion attack

Apache Cordova App Harness Targeted in Dependency Confusion Attack

You are here: Home / General Cyber Security News / Apache Cordova App Harness Targeted in Dependency Confusion Attack
April 23, 2024

Researchers have recognized a dependency confusion vulnerability impacting an archived Apache task called Cordova Application Harness.

Dependency confusion attacks take put owing to the simple fact that deal managers verify the community repositories prior to private registries, so permitting a threat actor to publish a malicious deal with the very same name to a general public bundle repository.

This triggers the package supervisor to inadvertently obtain the fraudulent package from the public repository alternatively of the meant personal repository. If effective, it can have serious repercussions, this sort of as setting up all downstream consumers that put in the deal.

✔ Approved From Our Partners
AOMEI Backupper Lifetime

Protect and backup your data using AOMEI Backupper. AOMEI Backupper takes secure and encrypted backups from your Windows, hard drives or partitions. With AOMEI Backupper you will never be worried about loosing your data anymore.

Get AOMEI Backupper with 72% discount from an authorized distrinutor of AOMEI: SerialCart® (Limited Offer).

➤ Activate Your Coupon Code


Cybersecurity

A Might 2023 assessment of npm and PyPI packages saved in cloud environments by cloud security firm Orca unveiled that virtually 49% of companies are susceptible to a dependency confusion attack.

Although npm and other package deal professionals have considering that launched fixes to prioritize the private variations, application security company Legit Security explained it located the Cordova Application Harness challenge to reference an inside dependency named cordova-harness-client with out a relative file route.

The open-source initiative was discontinued by the Apache Computer software Basis (ASF) as of April 18, 2019.

As Legit Security shown, this still left the door extensive open up for a offer chain attack by uploading a destructive model beneath the similar name with a better variation variety, as a result creating npm to retrieve the bogus variation from the public registry.

Dependency Confusion Attack

With the bogus package attracting more than 100 downloads soon after getting uploaded to npm, it signifies that the archived venture is even now remaining set to use, possible posing extreme threats to customers.

In a hypothetical attack state of affairs, an attacker could hijack the library to provide malicious code that could be executed on the focus on host on offer installation.

Cybersecurity

The Apache security staff has given that addressed the challenge by getting possession of the cordova-harness-shopper bundle. It really is worth noting that companies are recommended to generate public offers as placeholders to prevent dependency confusion attacks.

“This discovery highlights the need to take into consideration third-party tasks and dependencies as potential weak inbound links in the program enhancement manufacturing unit, specifically archived open up-source initiatives that may possibly not obtain frequent updates or security patches,” security researcher Ofek Haviv mentioned.

“Despite the fact that it may feel tempting to depart them as is, these tasks have a tendency to have vulnerabilities that are not having attention and not likely to be fastened.”

Observed this post fascinating? Stick to us on Twitter  and LinkedIn to read through more special articles we submit.


Some areas of this short article are sourced from:
thehackernews.com

Previous Post: «webinar: learn proactive supply chain threat hunting techniques Webinar: Learn Proactive Supply Chain Threat Hunting Techniques
Next Post: CoralRaider Malware Campaign Exploits CDN Cache to Spread Info-Stealers coralraider malware campaign exploits cdn cache to spread info stealers»

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Primary Sidebar

Report This Article

Recent Posts

  • BREAKING: 7,000-Device Proxy Botnet Using IoT, EoL Systems Dismantled in U.S. – Dutch Operation
  • OtterCookie v4 Adds VM Detection and Chrome, MetaMask Credential Theft Capabilities
  • Initial Access Brokers Target Brazil Execs via NF-e Spam and Legit RMM Trials
  • Deploying AI Agents? Learn to Secure Them Before Hackers Strike Your Business
  • Malicious npm Packages Infect 3,200+ Cursor Users With Backdoor, Steal Credentials
  • Beyond Vulnerability Management – Can You CVE What I CVE?
  • Google Rolls Out On-Device AI Protections to Detect Scams in Chrome and Android
  • Chinese Hackers Exploit SAP RCE Flaw CVE-2025-31324, Deploy Golang-Based SuperShell
  • 38,000+ FreeDrain Subdomains Found Exploiting SEO to Steal Crypto Wallet Seed Phrases
  • SonicWall Patches 3 Flaws in SMA 100 Devices Allowing Attackers to Run Code as Root

Copyright © TheCyberSecurity.News, All Rights Reserved.