Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Bug]: Remote Webview debugging is enabled. #1488

Open
2 of 3 tasks
rakeshv1108 opened this issue Feb 15, 2023 · 7 comments
Open
2 of 3 tasks

[Bug]: Remote Webview debugging is enabled. #1488

rakeshv1108 opened this issue Feb 15, 2023 · 7 comments
Labels

Comments

@rakeshv1108
Copy link

rakeshv1108 commented Feb 15, 2023

What happened?

How can this Webview debugging mode be turned off?

I've included my release apk build in the Mobsf testing procedure to look for security flaws. Additionally, I received one serious problem from the Mobsf report for your package library. The screenshot for that report is attached. Please take action to fix the security problem.

Screen Shot 2023-02-15 at 12 07 09 PM

Thank you.

Steps to reproduce?

1. Create release android build apk.
2. Set up the Mobsf security checkup tool.
3. Analyse that same apk through that Mobsf tool.

What did you expect to happen?

I want to disable or remove that debugging line from the npm package code.

React Native OneSignal SDK version

Release 4.5.0

Which platform(s) are affected?

  • iOS
  • Android

Relevant log output

No response

Code of Conduct

  • I agree to follow this project's Code of Conduct
@mlblount45
Copy link

Has this issue been added to the project road map? any approximation date on when this will be addressed?

@samu-gataca
Copy link

Any new about this?

@emawby
Copy link
Contributor

emawby commented May 11, 2023

I apologize we do not have news yet, but we appreciate the bump! We will investigate

@emawby emawby added the Bug label May 11, 2023
@maxi-sante
Copy link

Any new?

@Redn4s
Copy link

Redn4s commented Oct 20, 2023

A pentest of our app revealed that Remote WebView debugging is activated. This was specifically found in OneSignal: com/onesignal/WebViewManager.java. We're use v4.5.1 of react-native-onesignal.

Any news about the issue yet?

@tair-rhyme
Copy link

seems like that is false positive, because of this, if you do not set logLevel to debug and higher it should be OK

@manish-chimera
Copy link

manish-chimera commented Apr 4, 2024

I am having similar issue with Onesignal Android SDK with version 5.1.7. how can we disable Remote WEBview debugging?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

No branches or pull requests

8 participants