SCA: security update for cordova-android (GHSA-gwpf-62xp-vrg6)

high Tenable Cloud Security Plugin ID 415352

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- Product: Apache Cordova Android 5.2.2 and earlier. The application calls methods of the Log class.
Messages passed to these methods (Log.v(), Log.d(), Log.i(), Log.w(), and Log.e()) are stored in a series
of circular buffers on the device. By default, a maximum of four 16 KB rotated logs are kept in addition
to the current log. The logged data can be read using Logcat on the device. When using platforms prior to
Android 4.1 (Jelly Bean), the log data is not sandboxed per application; any application installed on the
device has the capability to read data logged by other applications. (CVE-2016-6799)

See Also

https://github.com/advisories/GHSA-gwpf-62xp-vrg6

Plugin Details

Severity: High

ID: 415352

Version: Revision 1.5

Type: Local

Family: SCA Checks

Published: 1/23/2025

Updated: 7/2/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Medium

Score: 5

Percentile: 95.09

Vendor

Vendor Severity: High

CVSS v2

Risk Factor: Medium

Base Score: 5

Temporal Score: 3.7

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:N

CVSS Score Source: CVE-2016-6799

CVSS v3

Risk Factor: High

Base Score: 7.5

Temporal Score: 6.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 9/11/2020

Vulnerability Publication Date: 5/9/2017

Reference Information

CVE: CVE-2016-6799

BID: 98365

cwe: CWE-532