Описание
Due to a misconfiguration in the manifest file of the WARP client for Android, it was possible to a perform a task hijacking attack. An attacker could create a malicious mobile application which could hijack legitimate app and steal potentially sensitive information when installed on the victim's device.
Ссылки
- ProductThird Party Advisory
- ProductThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 6.20 (исключая)
cpe:2.3:a:cloudflare:warp:*:*:*:*:*:android:*:*
EPSS
Процентиль: 17%
0.00056
Низкий
5.5 Medium
CVSS3
5.5 Medium
CVSS3
Дефекты
CWE-200
NVD-CWE-noinfo
EPSS
Процентиль: 17%
0.00056
Низкий
5.5 Medium
CVSS3
5.5 Medium
CVSS3
Дефекты
CWE-200
NVD-CWE-noinfo