CVE-2014-4925 HTML injection in Good For Enterprise Android

1. Vulnerability Properties

Title: HTML Injection in Good for Enterprise Android

CVE ID: CVE-2014-4925

CVSSv2 Base Score: 6.4 (AV:N/AC:L/Au:N/C:P/I:P/A:N)

Vendor: Good Technology (http://www1.good.com/)

Products: Good for Enterprise Android (possibly others)

Advisory Release Date: 8 January 2015

Advisory URL: http://labs.integrity.pt/advisories/cve-2014-4925/

Credits: Discovery and PoC by Cláudio André <ca[at]integrity.pt>

2. Vulnerability Summary

A remote attacker is able to send a crafted email with a payload that redirects the user to a target url as soon as he opens the email.

3. Technical Details

The vulnerability can be confirmed by sending a HTML email with the following content:

<meta http-equiv="refresh" content="0;URL='http://www.maliciousurl.com'" />

Exploiting this vulnerability could allow an attacker to redirect a user to a malicious website, allowing hooking the browser with malicious JavaScript, launching phishing attacks, etc.

4. Vulnerable Versions

Confirmed on version 1.9.0.40, but from the vendor feedback all versions up to 2.8.0.398 should be vulnerable.

5. Solution

Currently there is none. The vendor has classified this issue as unfixable and a product limitation.

6. Vulnerability Timeline

16 Apr 2014 – Vulnerability reported to vendor

7 Jan 2015 – Vendor gave final feedback that the issue was not a vulnerability and instead being a product limitation and unfixable.

8 Jan 2015 - Public disclosure

8 Jan 2015 - Vendor contacted us with feedback that a fix is in now progress, so a patched version is expected soon.

27 Jan 2015 - Vendor released patched version to the app stores. Version 2.8.1.402 released.