Skip to content
This repository has been archived by the owner on Jun 13, 2024. It is now read-only.

X509TrustManager vulnerability - deadline given, app removal warning #17

Closed
norkator opened this issue Jul 12, 2020 · 6 comments · Fixed by #18
Closed

X509TrustManager vulnerability - deadline given, app removal warning #17

norkator opened this issue Jul 12, 2020 · 6 comments · Fixed by #18
Assignees
Labels
bug Something isn't working good first issue Good for newcomers

Comments

@norkator
Copy link
Owner

Security alert

Your app is using an unsafe implementation of the X509TrustManager interface with an Apache HTTP client, resulting in a security vulnerability. Please see this Google Help Centre article for details, including the deadline for fixing the vulnerability.

Vulnerable classes:

com.nitramite.courier.ArraPakettiStrategy$1
com.nitramite.courier.CainiaoStrategy$1
com.nitramite.courier.DHLActiveTrackingStrategy$1
com.nitramite.courier.DHLAmazonStrategy$1
com.nitramite.courier.DHLExpressStrategy$1
com.nitramite.courier.FedExStrategy$1
com.nitramite.courier.GlsStrategy$1
com.nitramite.courier.MatkahuoltoStrategy$1
com.nitramite.courier.PostNordStrategy$1
com.nitramite.courier.PostiStrategy$1
com.nitramite.courier.UPSStrategy$1
Please fix the issue before: 10/08/2020

Affects APK version 119.

"After the deadlines shown in your Play Console, any apps that contain unfixed security vulnerabilities may be removed from Google Play."

@norkator norkator self-assigned this Jul 12, 2020
@norkator norkator added bug Something isn't working good first issue Good for newcomers labels Jul 12, 2020
@developerfromjokela
Copy link
Collaborator

developerfromjokela commented Jul 12, 2020 via email

@norkator
Copy link
Owner Author

Yep, good approach.

@norkator
Copy link
Owner Author

@norkator
Copy link
Owner Author

Got DHL Active tracking working at same time, url and headers needed changes

@norkator
Copy link
Owner Author

All other DHL services URL's have changed so can fix others too.

@norkator norkator linked a pull request Jul 13, 2020 that will close this issue
@norkator
Copy link
Owner Author

@developerfromjokela there is now pull request waiting review #18

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
bug Something isn't working good first issue Good for newcomers
Projects
None yet
Development

Successfully merging a pull request may close this issue.

2 participants