@havesource/cordova-plugin-push is vulnerable to Improper Export of Android Application Components
60
Medium Risk
Affected versions of this package set the android:exported attribute to true for certain components in the AndroidManifest.xml file. This setting allows those components (such as activities, services, or broadcast receivers) to be invoked by external applications. If not properly restricted, this configuration can increase the risk of unauthorized access, privilege escalation, or unintended data exposure.
You are affected if you are using a version that falls within the vulnerable range.
@havesource/cordova-plugin-push is vulnerable to Improper Export of Android Application Components in versions 5.0.0 - 5.0.5, 4.0.0 - 4.0.0, 3.0.0 - 3.0.1, 2.0.0 - 2.0.0 and 1.0.0 - 1.0.0.
Upgrade the @havesource/cordova-plugin-push library to the patch version.
Secure your code, cloud, and runtime environments in one central system. Find and fix vulnerabilities automatically.
No credit card required | Scan results in 32secs.
SOC 2Compliant
ISO 27001Compliant