CVE-2015-8320

Currently unrated

Key Information:

Vendor
Apache
Status
Vendor
CVE Published:
23 November 2015

Summary

Apache Cordova-Android before 3.7.0 improperly generates random values for BridgeSecret data, which makes it easier for attackers to conduct bridge hijacking attacks by predicting a value.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.