Apache Software Foundation Apache Cordova Android vulnerabilities
2 known vulnerabilities affecting apache_software_foundation/apache_cordova_android.
Total CVEs
2
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH2
Vulnerabilities
Page 1 of 1
CVE-2017-3160HIGHCVSS 7.4vApache Cordova 6.1.0 and below2018-02-01
CVE-2017-3160 [HIGH] CVE-2017-3160: After the Android platform is added to Cordova the first time, or after a project is created using t
After the Android platform is added to Cordova the first time, or after a project is created using the build scripts, the scripts will fetch Gradle on the first build. However, since the default URI is not using https, it is vulnerable to a MiTM and the Gradle executable is not safe. The severity of this issue is high due to the fact that the build scripts imme
cvelistv5nvd
CVE-2016-6799HIGHCVSS 7.5v5.2.2 and earlier2017-05-09
CVE-2016-6799 [HIGH] CWE-532 CVE-2016-6799: Product: Apache Cordova Android 5.2.2 and earlier. The application calls methods of the Log class. M
Product: Apache Cordova Android 5.2.2 and earlier. The application calls methods of the Log class. Messages passed to these methods (Log.v(), Log.d(), Log.i(), Log.w(), and Log.e()) are stored in a series of circular buffers on the device. By default, a maximum of four 16 KB rotated logs are kept in addition to the current log. The logged data can be re
cvelistv5nvd