8000 Play Core Library 1.7.0 is vulnerable · Issue #9 · dioKaratzas/android-inapp-update · GitHub
[go: up one dir, main page]
More Web Proxy on the site http://driver.im/
Skip to content
Play Core Library 1.7.0 is vulnerable #9
Open
@josevarghese

Description

@josevarghese

Describe the bug
The com.google.android.play:core:1.7.0, which is used within the dependency, is vulnerable, and Google recommends updating the Play Core Library to the latest version (1.7.2 or above)

To Reproduce

  1. Upload the APK to Google Play Store
  2. Within the Messages, you will get a warning like "Your latest production release contains SDK issues"

Critical issues have been reported with the following SDK versions: com.google.android.play:core:1.7.0 What the SDK developer told us: Your app contains a vulnerability that can lead to an attacker writing data to your app's internal storage. This is because your app is using an old version of the Play Core Library. Update the Play Core Library in your app to the latest version (1.7.2 or above).

Screenshots
critical issue

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions

      0