michaeltroger / greenpass-android

Green Pass PDF Wallet Android App
https://play.google.com/store/apps/details?id=com.michaeltroger.gruenerpass
GNU General Public License v3.0
73 stars 3 forks source link

Potentially vulnerable PDF library used #68

Closed SkewedZeppelin closed 1 year ago

SkewedZeppelin commented 2 years ago

I am going though apps that use old native libraries on F-Droid: https://gitlab.com/fdroid/fdroiddata/-/merge_requests/11496/

Your app uses com.tom-roush:pdfbox-android:2.0.1.0 using PDFBox 2.0.1 from 2016-04-22, which seems to have ~5 known security issues. https://github.com/michaeltroger/greenpass-android/blob/40/app/build.gradle#L99

Newer versions are available: https://github.com/TomRoush/PdfBox-Android/releases

michaeltroger commented 1 year ago

Done, please feel free to open a PR next time