Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Google play Vulnerability #92

Open
nimrodnan opened this issue May 18, 2018 · 1 comment
Open

Google play Vulnerability #92

nimrodnan opened this issue May 18, 2018 · 1 comment

Comments

@nimrodnan
Copy link

Apk在google play上架,提示 Vulnerability问题。具体如下:
com.ksyun.media.player.https.a$2$1
com.ksyun.media.streamer.util.https.KsyHttpConnection$2$1

提示APK采用不安全的 HostnameVerifier 接口实施方式的开发者。在与使用 setDefaultHostnameVerifier API 的远程主机建立 HTTPS 连接时,这种实施方式会接受所有主机名,从而使您的应用容易受到中间人攻击。攻击者可能会读取传输的数据(例如登录凭据),甚至更改通过 HTTPS 连接传输的数据。

@sujia
Copy link
Contributor

sujia commented Jun 4, 2018

这个问题已解决,请更新SDK版本,具体版本请查看release note

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants