CVE-2016-6799 describes an information disclosure vulnerability in Apache Cordova Android versions 5.2.2 and earlier. The application's use of the Log class methods (e.g., Log.v(), Log.d()) stores sensitive data in device log buffers, which can be accessed via Logcat. On Android versions prior to 4.1, any installed application can read these logs, potentially exposing confidential information. This vulnerability is rated High severity (CVSS 7.5), with a network attack vector and low complexity, leading to a high impact on confidentiality. There is no impact on integrity or availability. Currently, there is no evidence of active exploitation, and no public exploit code (Metasploit, Nuclei, ExploitDB) is available. Community discussion and media coverage for this CVE are minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 5.2.2CPE matchmatch criteria | cpe:2.3:a:apache:cordova:*:*:*:*:*:android:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.