Solved

IFS Field Service using unsecure functions on android

  • 1 October 2019
  • 2 replies
  • 180 views

Userlevel 3
Badge +6
We have observed IFS Field Service using unsecure functions on android. The mobile application is using com.aviary.android.feather.common.utils.IOUtils.unzipEntry in an unsecure way. See https://support.google.com/faqs/answer/9294009 for specs on how to fix the issue. We are using FSM 5.7. update 6. Do you have any idea if this has been looked in already?
icon

Best answer by Dhanushki Pahathkumbure 1 October 2019, 12:09

View original

2 replies

Userlevel 4
Badge +15
This issue identified by Google is in an unused library contained with the third party Aviary SDK and does not pose a security risk. The FSM Mobile solution uses that SDK only to allow users to edit attached images.
Userlevel 3
Badge +6

This third party Aviary SDK and does not pose a security risk. The FSM Mobile solution uses that SDK only to allow users to edit attached images.

 

Reply