h***@5000m.com
h***@5000m.com
  • 发布:2023-11-28 17:10
  • 更新:2023-11-28 17:10
  • 阅读:530

Fortify 漏洞扫描工具测试出安全漏洞

分类:HBuilderX

Fortify 漏洞扫描工具测试出安全漏洞,该如何解决
Android Bad Practices: Missing Google Play Services Updated SecurityProvider

Summary
The application does not utilize the Google Play Services to update the security Provider
Explanation
Android relies on the security Provider to provide secure network communications. The default devicecryptographic libraries are typically older versions of OpenSSL that contain known flaws. To overcomethis, Google provides a mechanism for an application to "patch" their local copy of OpenSSL via theGoogle Play Services ProviderInstaller client. It's been determined that the app is not using theupdated provider, leaving the application exposed to older known OpenSSL vulnerabilities andweaknesses.

2023-11-28 17:10 负责人:无 分享
已邀请:

要回复问题请先登录注册