Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Security alert on Cross App Scripting Vulnerability #439

Open
mosess opened this issue Mar 22, 2021 · 3 comments
Open

Security alert on Cross App Scripting Vulnerability #439

mosess opened this issue Mar 22, 2021 · 3 comments

Comments

@mosess
Copy link

mosess commented Mar 22, 2021

We're using the Data Theorem mobile security too and getting the following high priority alert:

Google Play Blocker: Cross App Scripting Vulnerability
The following Java or Kotlin Activities contain WebViews that are vulnerable to Cross App Scripting: com.box.androidsdk.content.auth.OAuthActivity

WebViews that enable JavaScript and load data read from untrusted Intents can be tricked by malicious Apps into executing JavaScript code in an unsafe context.

Is this a known issue? is there a plan for getting it fixed?
I can post their recommended solutions if needed.

*. we're currently using version 5.0.0 which is available on Maven but I can't find any reference for it in the repository releases, should we change it to the latest one shown here? (4.2.3)

@swfree
Copy link
Contributor

swfree commented Mar 22, 2021

Hi @mosess, thanks for reporting this issue. We'll take a look into the security vulnerability and get back to you soon with an update on when we can get this fixed.

Regarding the version, you'll want to use 4.2.3. The 5.0.0 version on Maven looks like it may have been a mistake that we'll look into removing.

@mosess
Copy link
Author

mosess commented Jul 5, 2021

Hey
Any news about this one?
I saw there's a merged fix, is there a plan to release an updated SDK version with it?

@arash-autodesk
Copy link

Hey Gang (@swfree )
Any update on this. was this fixed release?

I don't see any more releases after Mar 18 2019 https://github.com/box/box-android-sdk/releases

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants