FolioReader-Android icon indicating copy to clipboard operation
FolioReader-Android copied to clipboard

Google play console vulnerability alert

Open KateFacemetrics opened this issue 5 years ago • 11 comments

There is an Alert on Google play console saying that jquery-3.1.1 has known security issue and it should be updated to the latest version.

jquery-3.1.1.min.js is placed in the following folder: folioreader/src/main/assets/js/

Issue / Feature - FolioReader version - 0.5.4 FolioReader Stock / Modified -
Android SDK - Mobile / Tablet / Emulator Info -
Crash / Error -

Steps to reproduce / Describe in detail -

KateFacemetrics avatar Oct 14 '19 07:10 KateFacemetrics

same problem but check this pull request #417

KishanViramgama avatar Oct 16 '19 03:10 KishanViramgama

@KishanViramgama Did you find any solution for this?

ashokkumar88 avatar Nov 02 '19 07:11 ashokkumar88

@ashokkumar88 check this pull request #417

KishanViramgama avatar Nov 02 '19 10:11 KishanViramgama

@KishanViramgama did you solve this problem?

lainara6-zz avatar Nov 15 '19 02:11 lainara6-zz

@LayChannara i updated the jquery version to latest and rebuild it.

ashokkumar88 avatar Nov 15 '19 02:11 ashokkumar88

@ashokkumar88 Thanks

lainara6-zz avatar Nov 15 '19 02:11 lainara6-zz

Hi, how did you update it to latest version? Cannot edit the files inside the epub jar files/library. Please list the steps on achieving this. thank you.

changloka avatar Nov 30 '19 09:11 changloka

@changloka the steps mentioned here. https://github.com/FolioReader/FolioReader-Android/issues/316#issuecomment-449940637

ashokkumar88 avatar Nov 30 '19 10:11 ashokkumar88

Anybody able to find a solution to Play Console Vulnerability alert? I am still looking for a solution. I downloaded code of library from git and it does include jquery verstion 3.4.1 but it still fetches jquery version 3.1.1 through implementation. How to fix?

@hrishikesh-kadam link provided for RootFolder does not work anymore so can not see what is done to fix.

akhileshsharma avatar Jun 05 '20 09:06 akhileshsharma

Hi, Will this issue also come when I will use only Dependency of folio reader not Add the downloaded Folio reader as Library ? I'm also getting this issue. I'm currently using downloaded code of folio reader library and added in my App as a library.

mtamailindia avatar Jul 29 '20 11:07 mtamailindia

check this pull request #417

KishanViramgama avatar Jul 29 '20 14:07 KishanViramgama