Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

iOS AppCritique Vulnerability Found: Takes Over Certificate Validation Process #5507

Closed
corpetty opened this issue Aug 14, 2018 · 2 comments
Closed

Comments

@corpetty
Copy link
Contributor

corpetty commented Aug 14, 2018

Note:

This is an issue created from the Dark Labs AppCritique Static Analysis Report performed on Aug 14, 2018 on Status version 0.9.26 build 6382

Some of these may be purposeful and taken care of. If so, please provide reasoning here and it will be closed upon review. This issue will then serve as a reference for future potential vulnerability disclosures.

Description:

The app takes over the certificate validation process. This could
be used to implement certificate pinning, which is a best practice.
If used for other purposes, such as accepting all certificates, this
could present a security risk.

OWASP

2016-M3-Insecure Communication

@churik
Copy link
Member

churik commented Dec 5, 2022

Hello, @corpetty!
Is this one still relevant?

@cammellos
Copy link
Member

Closing as this is used for us to validate certificates from the backend, which has been discussed with security

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

3 participants