Sensitive data was found to be contained within CFURLConnection calls. This finding is to show the presence of data being sent over the network, but does not indicate an issue with the SSL/TLS implementation. The evidence table displays each data type, the actual value that was recovered, whether this value was recovered in plain text form or a specific encoding, the URL called which contained this data, and the data that was found to contain the sensitive value.
Steps to Reproduce
CFURLConnection requests are analyzed to determine if any sensitive data is transmitted over the network.
Finding Description
Sensitive data was found to be contained within CFURLConnection calls. This finding is to show the presence of data being sent over the network, but does not indicate an issue with the SSL/TLS implementation. The evidence table displays each data type, the actual value that was recovered, whether this value was recovered in plain text form or a specific encoding, the URL called which contained this data, and the data that was found to contain the sensitive value.
Steps to Reproduce
CFURLConnection requests are analyzed to determine if any sensitive data is transmitted over the network.
Risk and Regulatory Information
Severity: info
Application
See more detail in the NowSecure Report