Junglewise Threat Intelligence

CVE-2021-43849: cordova-plugin-fingerprint-aio intent handling DoS

CVE-2021-43849 · Severity: low · CVSS 3.1 · Published 2023-11-02

Vendors: npm.

Executive brief

cordova-plugin-fingerprint-aio is a Cordova plugin that enables biometric fingerprint authentication in mobile applications. An attacker can send a specially crafted intent to the vulnerable Android activity, causing the app to crash or become unresponsive. Repeated attacks can deny service to legitimate users, disrupting app availability.

Technical details

The vulnerability is an improper access control flaw (CWE-284) in the de.niklasmerz.cordova.biometric.BiometricActivity Android component. The activity is exported by default in affected versions, allowing third-party apps or remote attackers to send malicious intents with invalid or empty extras. This causes the app to crash. The attack vector is local/adjacent (via intent from another app on the device), requires no privileges or user interaction, and can be repeated to create a persistent denial of service. The fix in version 5.0.1 sets android:exported="false" to prevent external apps from accessing the activity.

Affected products

  • Niklas Merz cordova-plugin-fingerprint-aio all versions before 5.0.1

Timeline

  • 2021-12-23: disclosed
  • 2021-12-23: patched: version 5.0.1 released

References