Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Outdated APK version on App Store #2429

Open
GabeChiarelli opened this issue Jul 19, 2024 · 0 comments
Open

Outdated APK version on App Store #2429

GabeChiarelli opened this issue Jul 19, 2024 · 0 comments

Comments

@GabeChiarelli
Copy link

It looks like the APK version was updated to 3.19 about six months ago in master, but the App Store build still hasn't been updated with this version.

This means that the App Store version is still using the 3.14 repository, which appears to contain out of date packages that could present a security risk.

For example, the version of OpenSSH in this repository is 8.6p1, which is more than three years out of date and has some nasty CVEs. Although they are unlikely to escape the sandbox, sensitive data inside the sandbox such as private keys could still be exfiltrated if it were compromised.

Assuming that there are more than a few users that intend to use iSH for remote management or other tasks that require the use of SSH, this is a security hole that should be closed.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

1 participant