Pushwoosh / pushwoosh-phonegap-plugin

Pushwoosh PhoneGap Build Plugin
Other
109 stars 139 forks source link

Zip Path Traversal Vulnerability #320

Closed ipehimanshu closed 4 years ago

ipehimanshu commented 4 years ago

Security alert

Your app contains an unsafe unzipping pattern that may lead to a Path Traversal vulnerability. Please see this Google Help Center article to learn how to fix the issue.

Vulnerable locations:

com.pushwoosh.internal.utils.e.a

wfhm commented 4 years ago

Hi @ipehimanshu,

Please note that this issue is already fixed with the version 7.14.0 of our plugin. Please update the version of the Pushwoosh plugin in your app to the latest one in order to fix this warning(7.17.1).

https://github.com/Pushwoosh/pushwoosh-phonegap-plugin/releases/tag/7.17.1