Skip to main content
Solved

IFS Field Service using unsecure functions on android

  • October 1, 2019
  • 2 replies
  • 181 views

Chandima Athukorala
Hero (Employee)
Forum|alt.badge.img+6
We have observed IFS Field Service using unsecure functions on android. The mobile application is using com.aviary.android.feather.common.utils.IOUtils.unzipEntry in an unsecure way. See https://support.google.com/faqs/answer/9294009 for specs on how to fix the issue. We are using FSM 5.7. update 6. Do you have any idea if this has been looked in already?

Best answer by Dhanushki Pahathkumbure

This issue identified by Google is in an unused library contained with the third party Aviary SDK and does not pose a security risk. The FSM Mobile solution uses that SDK only to allow users to edit attached images.

2 replies

Dhanushki Pahathkumbure
Hero (Employee)
Forum|alt.badge.img+15
This issue identified by Google is in an unused library contained with the third party Aviary SDK and does not pose a security risk. The FSM Mobile solution uses that SDK only to allow users to edit attached images.

Forum|alt.badge.img+6
  • Sidekick
  • 16 replies
  • November 29, 2019

This third party Aviary SDK and does not pose a security risk. The FSM Mobile solution uses that SDK only to allow users to edit attached images.