Apache Cordova-Android before 3.7.0 improperly generates...
Moderate severity
Unreviewed
Published
May 14, 2022
to the GitHub Advisory Database
•
Updated Feb 2, 2023
Description
Published by the National Vulnerability Database
Nov 23, 2015
Published to the GitHub Advisory Database
May 14, 2022
Last updated
Feb 2, 2023
Apache Cordova-Android before 3.7.0 improperly generates random values for BridgeSecret data, which makes it easier for attackers to conduct bridge hijacking attacks by predicting a value.
References