导航菜单

应用安全检测报告

应用安全检测报告,支持文件搜索、内容检索和AI代码分析

移动应用安全检测报告

应用图标

DBA v2506090350

Android APK a3b10919...
44
安全评分

安全基线评分

44/100

中风险

综合风险等级

风险等级评定
  1. A
  2. B
  3. C
  4. F

应用存在一定安全风险,建议优化

漏洞与安全项分布

6 高危
22 中危
3 信息
2 安全

隐私风险评估

6
第三方跟踪器

高隐私风险
检测到大量第三方跟踪器


检测结果分布

高危安全漏洞 6
中危安全漏洞 22
安全提示信息 3
已通过安全项 2
重点安全关注 0

高危安全漏洞 应用程序使用带PKCS5/PKCS7填充的加密模式CBC。此配置容易受到填充oracle攻击。

应用程序使用带PKCS5/PKCS7填充的加密模式CBC。此配置容易受到填充oracle攻击。
https://github.com/OWASP/owasp-mstg/blob/master/Document/0x04g-Testing-Cryptography.md#identifying-insecure-andor-deprecated-cryptographic-algorithms-mstg-crypto-4

Files:
com/nimbusds/jose/crypto/impl/AESCBC.java, line(s) 31
com/nimbusds/jose/jca/JCASupport.java, line(s) 174

高危安全漏洞 已启用远程WebView调试

已启用远程WebView调试
https://github.com/OWASP/owasp-mstg/blob/master/Document/0x04c-Tampering-and-Reverse-Engineering.md#debugging-and-tracing

Files:
com/adnuntius/android/sdk/AdnuntiusAdWebView.java, line(s) 64,8
com/sourcepoint/cmplibrary/core/web/ConsentWebView.java, line(s) 216,11

高危安全漏洞 如果一个应用程序使用WebView.loadDataWithBaseURL方法来加载一个网页到WebView,那么这个应用程序可能会遭受跨站脚本攻击

如果一个应用程序使用WebView.loadDataWithBaseURL方法来加载一个网页到WebView,那么这个应用程序可能会遭受跨站脚本攻击
https://github.com/OWASP/owasp-mstg/blob/master/Document/0x05h-Testing-Platform-Interaction.md#static-analysis-7

Files:
com/braze/ui/inappmessage/views/InAppMessageHtmlBaseView.java, line(s) 209,13

高危安全漏洞 该文件是World Writable。任何应用程序都可以写入文件

该文件是World Writable。任何应用程序都可以写入文件
https://github.com/OWASP/owasp-mstg/blob/master/Document/0x05d-Testing-Data-Storage.md#testing-local-storage-for-sensitive-data-mstg-storage-1-and-mstg-storage-2

Files:
io/refiner/Refiner.java, line(s) 165,322

高危安全漏洞 使用弱加密算法

使用弱加密算法
https://github.com/OWASP/owasp-mstg/blob/master/Document/0x04g-Testing-Cryptography.md#identifying-insecure-andor-deprecated-cryptographic-algorithms-mstg-crypto-4

Files:
no/finn/storage/SecurePreferences.java, line(s) 63,65

高危安全漏洞 应用程序包含隐私跟踪程序

此应用程序有多个6隐私跟踪程序。跟踪器可以跟踪设备或用户,是终端用户的隐私问题。

中危安全漏洞 Activity (com.schibsted.nmp.AccountRedirectActivity) 未受保护。

[android:exported=true]
检测到  Activity 已导出,未受任何权限保护,任意应用均可访问。

中危安全漏洞 Content Provider (com.m10s.identity.webflows.loginPrompt.LoginPromptContentProvider) 未受保护。

[android:exported=true]
检测到  Content Provider 已导出,未受任何权限保护,任意应用均可访问。

中危安全漏洞 Activity (androidx.compose.ui.tooling.PreviewActivity) 未受保护。

[android:exported=true]
检测到  Activity 已导出,未受任何权限保护,任意应用均可访问。

中危安全漏洞 Service (androidx.work.impl.background.systemjob.SystemJobService) 受权限保护,但应检查权限保护级别。

Permission: android.permission.BIND_JOB_SERVICE [android:exported=true]
检测到  Service 已导出并受未在本应用定义的权限保护。请在权限定义处核查其保护级别。若为 normal 或 dangerous,恶意应用可申请并与组件交互;若为 signature,仅同证书签名应用可访问。

中危安全漏洞 Broadcast Receiver (androidx.work.impl.diagnostics.DiagnosticsReceiver) 受权限保护,但应检查权限保护级别。

Permission: android.permission.DUMP [android:exported=true]
检测到  Broadcast Receiver 已导出并受未在本应用定义的权限保护。请在权限定义处核查其保护级别。若为 normal 或 dangerous,恶意应用可申请并与组件交互;若为 signature,仅同证书签名应用可访问。

中危安全漏洞 Service (com.google.android.gms.auth.api.signin.RevocationBoundService) 受权限保护,但应检查权限保护级别。

Permission: com.google.android.gms.auth.api.signin.permission.REVOCATION_NOTIFICATION [android:exported=true]
检测到  Service 已导出并受未在本应用定义的权限保护。请在权限定义处核查其保护级别。若为 normal 或 dangerous,恶意应用可申请并与组件交互;若为 signature,仅同证书签名应用可访问。

中危安全漏洞 Broadcast Receiver (com.google.firebase.iid.FirebaseInstanceIdReceiver) 受权限保护,但应检查权限保护级别。

Permission: com.google.android.c2dm.permission.SEND [android:exported=true]
检测到  Broadcast Receiver 已导出并受未在本应用定义的权限保护。请在权限定义处核查其保护级别。若为 normal 或 dangerous,恶意应用可申请并与组件交互;若为 signature,仅同证书签名应用可访问。

中危安全漏洞 Activity (androidx.test.core.app.InstrumentationActivityInvoker$BootstrapActivity) 未受保护。

[android:exported=true]
检测到  Activity 已导出,未受任何权限保护,任意应用均可访问。

中危安全漏洞 Activity (androidx.test.core.app.InstrumentationActivityInvoker$EmptyActivity) 未受保护。

[android:exported=true]
检测到  Activity 已导出,未受任何权限保护,任意应用均可访问。

中危安全漏洞 Activity (androidx.test.core.app.InstrumentationActivityInvoker$EmptyFloatingActivity) 未受保护。

[android:exported=true]
检测到  Activity 已导出,未受任何权限保护,任意应用均可访问。

中危安全漏洞 Broadcast Receiver (androidx.profileinstaller.ProfileInstallReceiver) 受权限保护,但应检查权限保护级别。

Permission: android.permission.DUMP [android:exported=true]
检测到  Broadcast Receiver 已导出并受未在本应用定义的权限保护。请在权限定义处核查其保护级别。若为 normal 或 dangerous,恶意应用可申请并与组件交互;若为 signature,仅同证书签名应用可访问。

中危安全漏洞 文件可能包含硬编码的敏感信息,如用户名、密码、密钥等

文件可能包含硬编码的敏感信息,如用户名、密码、密钥等
https://github.com/OWASP/owasp-mstg/blob/master/Document/0x05d-Testing-Data-Storage.md#checking-memory-for-sensitive-data-mstg-storage-10

Files:
bo/content/SdkAuthenticationCache.java, line(s) 84
com/braze/Constants.java, line(s) 49,55,67,47,48,83,29,30,53,54,31,51,62,46,66,68,76,61,90,74,93,36,45,92,12,13,16,17,18,96,50,60,69,75,89,72,91,57
com/braze/configuration/BrazeConfig.java, line(s) 1126,1126
com/braze/support/StringUtils.java, line(s) 30
com/m10s/identity/webflows/client/Client.java, line(s) 65
com/nimbusds/jose/HeaderParameterNames.java, line(s) 13
com/nimbusds/jose/jwk/JWKParameterNames.java, line(s) 6,16,17
com/schibsted/nmp/FrontpageGraphDirections.java, line(s) 121
com/schibsted/nmp/RootGraphDirections.java, line(s) 930,1031,1132,1233
com/schibsted/nmp/SearchNavigationArguments.java, line(s) 46
com/schibsted/nmp/categoriesexplorer/data/dtos/CategorySearchParameterDto.java, line(s) 69
com/schibsted/nmp/categoriesexplorer/data/dtos/CategorySearchTargetDto.java, line(s) 69
com/schibsted/nmp/categoriesexplorer/domain/models/CategoryNode.java, line(s) 116
com/schibsted/nmp/categoriesexplorer/domain/models/CategorySearchTarget.java, line(s) 67
com/schibsted/nmp/companyprofile/Schema.java, line(s) 110
com/schibsted/nmp/deeplinks/util/IntentHandlerUtil.java, line(s) 98
com/schibsted/nmp/foundation/adinput/ad/imageeditor/sorting/ImageSortingFragment.java, line(s) 43
com/schibsted/nmp/foundation/advertising/data/remote/models/config/ConfigRequest.java, line(s) 131
com/schibsted/nmp/foundation/advertising/data/remote/models/config/GamTargeting.java, line(s) 69
com/schibsted/nmp/foundation/advertising/displayadsconfig/GlimrManager.java, line(s) 44
com/schibsted/nmp/foundation/search/controller/UpdateUrlsAndReloadSearch.java, line(s) 67
com/schibsted/nmp/foundation/search/map/SearchMapState.java, line(s) 156
com/schibsted/nmp/foundation/search/navigation/SearchScreens.java, line(s) 127,235
com/schibsted/nmp/foundation/search/navigation/SearchTermWithKey.java, line(s) 66
com/schibsted/nmp/foundation/search/resultpage/SearchResultPageContainerStateKt.java, line(s) 10
com/schibsted/nmp/foundation/search/ui/compose/SearchResultComposeItem.java, line(s) 256
com/schibsted/nmp/frontpage/data/marketgrid/MarketSearchParameterDto.java, line(s) 69
com/schibsted/nmp/frontpage/data/marketgrid/MarketSearchTargetDto.java, line(s) 69
com/schibsted/nmp/frontpage/domain/models/marketgrid/MarketSearchTarget.java, line(s) 67
com/schibsted/nmp/frontpage/domain/models/orchestratedcontents/BannerInline.java, line(s) 66
com/schibsted/nmp/frontpage/domain/models/orchestratedcontents/BannerIntermingle.java, line(s) 65
com/schibsted/nmp/frontpage/domain/models/orchestratedcontents/RecommendationCrossbrand.java, line(s) 112
com/schibsted/nmp/frontpage/domain/models/orchestratedcontents/RecommendationExternal.java, line(s) 120
com/schibsted/nmp/frontpage/domain/models/orchestratedcontents/RecommendationNmp.java, line(s) 132
com/schibsted/nmp/job/itempage/MediaLinksView.java, line(s) 36
com/schibsted/nmp/job/itempage/results/AdditionalLink.java, line(s) 81
com/schibsted/nmp/job/search/container/fragment/JobSearchContainerFragmentArgs.java, line(s) 108
com/schibsted/nmp/job/search/container/fragment/JobSearchFragmentArgs.java, line(s) 134
com/schibsted/nmp/job/search/container/state/JobSearchResultPageContainerState.java, line(s) 139
com/schibsted/nmp/job/search/map/JobSearchMapFragmentArgs.java, line(s) 88
com/schibsted/nmp/job/search/resultpage/JobSearchPageScreenState.java, line(s) 142
com/schibsted/nmp/job/search/smartsearch/data/AISummaryRepository.java, line(s) 18
com/schibsted/nmp/mobility/itempage/MediaLinksView.java, line(s) 36
com/schibsted/nmp/mobility/itempage/boat/BoatDescriptionView.java, line(s) 42
com/schibsted/nmp/mobility/itempage/boat/BoatEquipmentView.java, line(s) 42
com/schibsted/nmp/mobility/itempage/car/CarSelfDeclarationView.java, line(s) 42
com/schibsted/nmp/mobility/itempage/motor/ChatButtonView.java, line(s) 50
com/schibsted/nmp/mobility/itempage/motor/MobilitySpecificationsView.java, line(s) 43
com/schibsted/nmp/mobility/itempage/motor/MotorAttributesView.java, line(s) 42
com/schibsted/nmp/mobility/itempage/motor/MotorClaimView.java, line(s) 45
com/schibsted/nmp/mobility/itempage/motor/MotorContractActionView.java, line(s) 67
com/schibsted/nmp/mobility/itempage/motor/MotorDescriptionView.java, line(s) 47
com/schibsted/nmp/mobility/itempage/motor/MotorEquipmentList.java, line(s) 42,45
com/schibsted/nmp/mobility/itempage/motor/MotorMultiPriceView.java, line(s) 41
com/schibsted/nmp/mobility/itempage/motor/VehiclePriceView.java, line(s) 39
com/schibsted/nmp/mobility/itempage/results/AdditionalLink.java, line(s) 81
com/schibsted/nmp/mobility/landingpage/LandingPageNavigationEvent.java, line(s) 92
com/schibsted/nmp/mobility/landingpage/api/CategoryItem.java, line(s) 129
com/schibsted/nmp/mobility/landingpage/api/CollectionItem.java, line(s) 124
com/schibsted/nmp/mobility/landingpage/api/LastSearchItem.java, line(s) 115
com/schibsted/nmp/mobility/landingpage/api/SearchParam.java, line(s) 71
com/schibsted/nmp/mobility/landingpage/domain/models/MobilityCategory.java, line(s) 127
com/schibsted/nmp/mobility/landingpage/domain/models/MobilityCollection.java, line(s) 122
com/schibsted/nmp/mobility/landingpage/domain/models/MobilityLastSearch.java, line(s) 113
com/schibsted/nmp/mobility/landingpage/domain/models/MobilitySearchParams.java, line(s) 64
com/schibsted/nmp/mobility/search/compose/MobilitySearchResultViewState.java, line(s) 158
com/schibsted/nmp/mobility/search/container/fragment/MobilitySearchContainerFragmentArgs.java, line(s) 108
com/schibsted/nmp/mobility/search/container/fragment/MobilitySearchFragmentArgs.java, line(s) 134
com/schibsted/nmp/mobility/search/container/state/MobilitySearchResultPageContainerState.java, line(s) 139
com/schibsted/nmp/mobility/search/map/MobilitySearchMapFragmentArgs.java, line(s) 88
com/schibsted/nmp/mobility/search/resultpage/MobilitySearchPageScreenState.java, line(s) 139
com/schibsted/nmp/realestate/itempage/MediaLinksView.java, line(s) 36
com/schibsted/nmp/realestate/itempage/results/AdditionalLink.java, line(s) 80
com/schibsted/nmp/realestate/search/container/fragment/RealEstateSearchContainerFragmentArgs.java, line(s) 110
com/schibsted/nmp/realestate/search/container/fragment/RealEstateSearchFragmentArgs.java, line(s) 135
com/schibsted/nmp/realestate/search/container/state/RealEstateSearchResultPageContainerState.java, line(s) 141
com/schibsted/nmp/realestate/search/map/RealEstateSearchMapFragmentArgs.java, line(s) 89
com/schibsted/nmp/realestate/search/resultpage/RealEstateSearchPageScreenState.java, line(s) 139
com/schibsted/nmp/realestate_client/model/breadcrumbs/BreadcrumbParameterDto.java, line(s) 82
com/schibsted/nmp/realestate_client/model/breadcrumbs/BreadcrumbsDto.java, line(s) 123
com/schibsted/nmp/recommerce/search/container/fragment/RecommerceSearchContainerFragmentArgs.java, line(s) 110
com/schibsted/nmp/recommerce/search/container/state/RecommerceSearchResultPageContainerState.java, line(s) 141
com/schibsted/nmp/recommerce/search/map/RecommerceSearchMapFragmentArgs.java, line(s) 89
com/schibsted/nmp/recommerce/search/navigation/RecommerceSearchScreens.java, line(s) 117
com/schibsted/nmp/recommerce/search/results/RecommerceSearchFragmentArgs.java, line(s) 135
com/schibsted/nmp/recommerce/search/results/RecommerceSearchPageScreenState.java, line(s) 139
com/schibsted/nmp/savedsearchdata/data/model/SavedSearch.java, line(s) 325,122
com/schibsted/nmp/savedsearchdata/data/model/SavedSearchApi.java, line(s) 174
com/schibsted/nmp/savedsearchdata/data/model/SavedSearchDb.java, line(s) 107
com/schibsted/nmp/trust/feedback/output/privatelisting/ui/items/DeletedIncomingReview.java, line(s) 130
com/schibsted/nmp/trust/feedback/output/privatelisting/ui/items/DeletedOutgoingReview.java, line(s) 130
com/schibsted/nmp/trust/feedback/output/privatelisting/ui/items/ExpiredIncomingReview.java, line(s) 116
com/schibsted/nmp/trust/feedback/output/privatelisting/ui/items/ExpiredReview.java, line(s) 116
com/schibsted/nmp/trust/feedback/output/privatelisting/ui/items/GivenReview.java, line(s) 129
com/schibsted/nmp/trust/feedback/output/privatelisting/ui/items/PendingIncomingReview.java, line(s) 116
com/schibsted/nmp/trust/feedback/output/privatelisting/ui/items/PendingReview.java, line(s) 116
com/schibsted/nmp/trust/feedback/output/privatelisting/ui/items/ReceivedReview.java, line(s) 124
com/schibsted/pulse/tracker/internal/config/ConfigurationConverter.java, line(s) 18,21,27
com/schibsted/pulse/tracker/internal/event/client/ConsentUpdater.java, line(s) 9
com/slack/api/methods/request/apps/AppsUninstallRequest.java, line(s) 116,46
com/slack/api/methods/request/chat/ChatPostEphemeralRequest.java, line(s) 372,157
com/slack/api/methods/request/chat/ChatPostMessageRequest.java, line(s) 471,218
com/slack/api/methods/request/oauth/OAuthAccessRequest.java, line(s) 158,77
com/slack/api/methods/request/oauth/OAuthTokenRequest.java, line(s) 158,77
com/slack/api/methods/request/oauth/OAuthV2AccessRequest.java, line(s) 186,87
com/slack/api/methods/request/oauth/OAuthV2ExchangeRequest.java, line(s) 116,46
com/slack/api/methods/request/openid/connect/OpenIDConnectTokenRequest.java, line(s) 186,87
com/slack/api/methods/response/admin/users/AdminUsersListResponse.java, line(s) 418
com/slack/api/methods/response/reactions/ReactionsGetResponse.java, line(s) 443
com/slack/api/methods/response/reactions/ReactionsListResponse.java, line(s) 804
com/slack/api/methods/response/rtm/RTMStartResponse.java, line(s) 1253
com/slack/api/methods/response/stars/StarsListResponse.java, line(s) 724
com/slack/api/methods/response/users/profile/UsersProfileSetResponse.java, line(s) 135
com/slack/api/model/AppCredentials.java, line(s) 86
com/slack/api/model/File.java, line(s) 3619,1700
com/slack/api/model/IntegrationLog.java, line(s) 236
com/slack/api/model/Latest.java, line(s) 375
com/slack/api/model/Login.java, line(s) 164
com/slack/api/model/MatchedItem.java, line(s) 2641,1849
com/slack/api/model/Message.java, line(s) 1996,1284,642
com/slack/api/model/event/AppMentionEvent.java, line(s) 335
com/slack/api/model/event/MessageBotEvent.java, line(s) 199
com/slack/api/model/event/MessageMeEvent.java, line(s) 171
com/slack/api/model/list/ListAttachment.java, line(s) 843,372
com/slack/api/model/list/ListColumn.java, line(s) 177,78
com/slack/api/model/list/ListRecord.java, line(s) 878,635
com/slack/api/model/list/ListView.java, line(s) 354,723,159,624
com/slack/api/model/list/ListViewColumn.java, line(s) 152,59
com/slack/api/scim/model/User.java, line(s) 353,353
com/slack/api/scim/response/ServiceProviderConfigsGetResponse.java, line(s) 63
com/slack/api/scim2/model/User.java, line(s) 353,353
com/slack/api/scim2/response/ServiceProviderConfigsGetResponse.java, line(s) 63
com/slack/api/token_rotation/TokenRotator.java, line(s) 88
com/slack/api/util/http/ProxyUrlUtil.java, line(s) 181,70
com/slack/api/webhook/Payload.java, line(s) 310,128
com/sourcepoint/cmplibrary/data/local/DataStorage.java, line(s) 37,165
com/sourcepoint/cmplibrary/data/local/DataStorageCcpa.java, line(s) 40,176
com/sourcepoint/cmplibrary/data/local/DataStorageGdpr.java, line(s) 16,171,19,174,13,168,22,177,37,192,85,240,88,243
com/sourcepoint/cmplibrary/model/exposed/TargetingParam.java, line(s) 61
com/vend/feedback/model/ExpiredFeedbackData.java, line(s) 99
com/vend/feedback/model/ExpiredIncomingFeedbackData.java, line(s) 99
com/vend/feedback/model/GivenFeedbackData.java, line(s) 127
com/vend/feedback/model/PendingFeedbackItemData.java, line(s) 114
com/vend/feedback/model/PendingIncomingFeedbackData.java, line(s) 99
com/vend/feedback/model/ReceivedFeedbackData.java, line(s) 102
io/ktor/client/request/forms/FormPart.java, line(s) 75
io/ktor/http/HttpHeaders.java, line(s) 223
io/ktor/http/auth/HttpAuthHeader.java, line(s) 60,78
no/finn/adlinks/AdLinksView.java, line(s) 35,38
no/finn/android/ABTesting.java, line(s) 42
no/finn/android/AppEnvironment.java, line(s) 47,65
no/finn/android/auth/VerificationManagerKt.java, line(s) 11
no/finn/android/auth/VerificationStoreKt.java, line(s) 10
no/finn/android/candidateprofile/data/JobProfileRepository.java, line(s) 24
no/finn/android/candidateprofile/marketfront/data/AISummaryRepository.java, line(s) 18
no/finn/android/candidateprofile/onboarding/data/OnboardingRepository.java, line(s) 43
no/finn/android/candidateprofile/salary/data/SalaryRepository.java, line(s) 30
no/finn/android/consent/ConsentSetting.java, line(s) 95
no/finn/android/data/SharedPreferencesToggleStoreKt.java, line(s) 10,13
no/finn/android/navigation/GlobalScreens.java, line(s) 1022,1147
no/finn/android/navigation/finnflow/PresenterContext.java, line(s) 21
no/finn/android/networking/NetConfig.java, line(s) 16,19,13,27,30,33,36,39,42
no/finn/android/notifications/settings/NotificationGroup.java, line(s) 35
no/finn/android/profile/verifieduser/VerifyUserFragment.java, line(s) 44,47
no/finn/android/recommendations/DiscoverServiceKt.java, line(s) 10
no/finn/android/screen/ScreenFragmentKt.java, line(s) 10
no/finn/android/settings/model/setting/SwitchSetting.java, line(s) 109
no/finn/android/settings/model/setting/ThemeSetting.java, line(s) 102
no/finn/android/track/ObjectShareCallbackReceiverKt.java, line(s) 17,20,23
no/finn/android/ui/globalsearch/GlobalSearchFragmentArgs.java, line(s) 86
no/finn/android/ui/globalsearch/GlobalSearchState.java, line(s) 125
no/finn/android/ui/snackbar/FadeInFadeOutAnimationItem.java, line(s) 63
no/finn/android/util/NotificationPermissionStorageKt.java, line(s) 13
no/finn/androidprivacy/consent/ConsentStoreImpl.java, line(s) 40,43,52,46
no/finn/bap/model/AdRecommerceBreadcrumbListData.java, line(s) 81
no/finn/bap/model/RecommerceBreadcrumbParameterData.java, line(s) 67
no/finn/bottomsheetfilter/filters/models/FilterResults.java, line(s) 161,84
no/finn/breadcrumbs/AdBreadcrumbListData.java, line(s) 82
no/finn/breadcrumbs/BreadcrumbParameterData.java, line(s) 68
no/finn/breadcrumbs/BreadcrumbParameterUI.java, line(s) 65
no/finn/breadcrumbs/BreadcrumbsUI.java, line(s) 79
no/finn/broadcast/SharedPreferencesDismissedBroadcastStorage.java, line(s) 21
no/finn/camera/CameraFragment.java, line(s) 75
no/finn/camera/workmanager/DeletePhotosWorkerKt.java, line(s) 13
no/finn/charcoal/controllers/filter/InAppSearch.java, line(s) 66
no/finn/charcoal/controllers/selection/LocationPersistenceManager.java, line(s) 32,36
no/finn/charcoal/controllers/selection/Query.java, line(s) 65
no/finn/charcoal/controllers/selection/QueryParameterData.java, line(s) 65
no/finn/charcoal/controllers/selection/RangeSelection.java, line(s) 75
no/finn/environment/BuildConfig.java, line(s) 16,9,22
no/finn/fcm/data/FCMInstanceIDStorage.java, line(s) 28
no/finn/jobapply/data/JobApplyRepository.java, line(s) 23,26
no/finn/jobapply/data/model/responses/Headers.java, line(s) 68
no/finn/nam2data/RecommerceCategory.java, line(s) 110
no/finn/objectpage/gallery/FullscreenGalleryFragment.java, line(s) 40
no/finn/promotions/contentcard/util/ContentCardUtilsKt.java, line(s) 38,29,32,35,41,44,47,53,56,59,50,62,65,68
no/finn/recommerce/camera/ui/RecommerceCameraFragment.java, line(s) 92
no/finn/searchdata/lastsearches/LastSearch.java, line(s) 79
no/finn/searchdata/lastsearches/LastSearchesSimpleCache.java, line(s) 126
no/finn/searchdata/marketfilter/Subvertical.java, line(s) 93
no/finn/storage/SecurePreferencesKt.java, line(s) 11
no/finn/trustcomponent/model/Question.java, line(s) 112
no/finn/trustcomponent/model/QuestionsList.java, line(s) 137
no/finn/trustcomponent/ui/feedbackrating/FeedbackInputData.java, line(s) 106
no/finn/ui/components/speclist/Attribute.java, line(s) 65
no/finntech/search/quest/Descriptions.java, line(s) 118
no/finntech/search/quest/MetaData.java, line(s) 245
no/finntech/search/quest/SubVertical.java, line(s) 82
no/finntech/search/quest/resultitem/BapResultEntry.java, line(s) 223
no/finntech/search/quest/resultitem/BoatResultEntry.java, line(s) 272
no/finntech/search/quest/resultitem/JobResultEntry.java, line(s) 218
no/finntech/search/quest/resultitem/MapResultEntry.java, line(s) 164
no/finntech/search/quest/resultitem/MotorResultEntry.java, line(s) 339
no/finntech/search/quest/resultitem/RealestateProjectResultEntry.java, line(s) 286
no/finntech/search/quest/resultitem/RealestateResultEntry.java, line(s) 330
org/constretto/Property.java, line(s) 36
org/javamoney/moneta/RoundedMoney.java, line(s) 33
org/javamoney/moneta/spi/CompoundRateProvider.java, line(s) 18
org/orbitmvi/orbit/viewmodel/ViewModelExtensionsKt.java, line(s) 25
org/prebid/mobile/Util.java, line(s) 14,15
org/prebid/mobile/rendering/models/openrtb/bidRequests/PluginRendererList.java, line(s) 9
org/prebid/mobile/rendering/sdk/deviceData/managers/UserConsentManager.java, line(s) 50,49,45,47,46,48

中危安全漏洞 不安全的Web视图实现。可能存在WebView任意代码执行漏洞

不安全的Web视图实现。可能存在WebView任意代码执行漏洞
https://github.com/OWASP/owasp-mstg/blob/master/Document/0x05h-Testing-Platform-Interaction.md#testing-javascript-execution-in-webviews-mstg-platform-5

Files:
com/adnuntius/android/sdk/AdnuntiusAdWebView.java, line(s) 60,61,62,54
com/example/hybrid/webview/InternalWebView.java, line(s) 127,126
com/schibsted/pulse/tracker/hybrid/PulseHybridWebController.java, line(s) 63,62
com/sourcepoint/cmplibrary/core/web/ConsentWebView.java, line(s) 172,209
io/refiner/ui/RefinerSurveyFragment.java, line(s) 155,351

中危安全漏洞 MD5是已知存在哈希冲突的弱哈希

MD5是已知存在哈希冲突的弱哈希
https://github.com/OWASP/owasp-mstg/blob/master/Document/0x04g-Testing-Cryptography.md#identifying-insecure-andor-deprecated-cryptographic-algorithms-mstg-crypto-4

Files:
com/braze/support/StringUtils.java, line(s) 107
no/finn/storage/SecurePreferences.java, line(s) 63,65,67
org/prebid/mobile/rendering/utils/helpers/Utils.java, line(s) 132

中危安全漏洞 SHA-1是已知存在哈希冲突的弱哈希

SHA-1是已知存在哈希冲突的弱哈希
https://github.com/OWASP/owasp-mstg/blob/master/Document/0x04g-Testing-Cryptography.md#identifying-insecure-andor-deprecated-cryptographic-algorithms-mstg-crypto-4

Files:
io/ktor/util/CryptoKt__CryptoJvmKt.java, line(s) 54
org/prebid/mobile/rendering/utils/helpers/Utils.java, line(s) 90

中危安全漏洞 应用程序使用不安全的随机数生成器

应用程序使用不安全的随机数生成器
https://github.com/OWASP/owasp-mstg/blob/master/Document/0x04g-Testing-Cryptography.md#weak-random-number-generators

Files:
bo/content/e1.java, line(s) 6
com/braze/support/IntentUtils.java, line(s) 15
com/schibsted/pulse/tracker/internal/network/BackoffStrategy.java, line(s) 5
com/schibsted/pulse/tracker/internal/network/NetworkDiModule.java, line(s) 23
net/bytebuddy/agent/builder/AgentBuilder.java, line(s) 38
net/bytebuddy/dynamic/TypeResolutionStrategy.java, line(s) 6
net/bytebuddy/utility/RandomString.java, line(s) 4
nl/dionsegijn/konfetti/ParticleSystem.java, line(s) 5
nl/dionsegijn/konfetti/emitters/RenderSystem.java, line(s) 6
nl/dionsegijn/konfetti/modules/LocationModule.java, line(s) 3
nl/dionsegijn/konfetti/modules/VelocityModule.java, line(s) 3
no/finn/android/notifications/push/PushMessageController.java, line(s) 9
org/junit/runner/manipulation/Ordering.java, line(s) 7
org/prebid/mobile/Util.java, line(s) 10
org/prebid/mobile/rendering/utils/helpers/Utils.java, line(s) 34

中危安全漏洞 应用程序使用SQLite数据库并执行原始SQL查询。原始SQL查询中不受信任的用户输入可能会导致SQL注入。敏感信息也应加密并写入数据库

应用程序使用SQLite数据库并执行原始SQL查询。原始SQL查询中不受信任的用户输入可能会导致SQL注入。敏感信息也应加密并写入数据库
https://github.com/OWASP/owasp-mstg/blob/master/Document/0x04h-Testing-Code-Quality.md#injection-flaws-mstg-arch-2-and-mstg-platform-2

Files:
com/m10s/identity/webflows/loginPrompt/SessionInfoDatabase.java, line(s) 6,7,35,41
no/finn/dbcommon/DbHelper.java, line(s) 6,7,8,175

中危安全漏洞 应用程序创建临时文件。敏感信息永远不应该被写进临时文件

应用程序创建临时文件。敏感信息永远不应该被写进临时文件


Files:
net/bytebuddy/dynamic/DynamicType.java, line(s) 2697
no/finn/android/ui/util/file/FileController.java, line(s) 253
no/finn/camera/utils/ImageUploadUtilsKt.java, line(s) 44
no/finn/camera/utils/UploadImageQueryHandler.java, line(s) 192
no/finn/nmpmessaging/conversation/data/AttachmentFileProvider.java, line(s) 45
org/ini4j/Reg.java, line(s) 227
org/junit/rules/TemporaryFolder.java, line(s) 76,160

中危安全漏洞 IP地址泄露

IP地址泄露


Files:
com/nimbusds/jose/jwk/Curve.java, line(s) 19,20,23,24,25
io/ktor/network/sockets/TcpSocketBuilder.java, line(s) 74
io/ktor/network/sockets/UDPSocketBuilder.java, line(s) 80

中危安全漏洞 可能存在跨域漏洞。在 WebView 中启用从 URL 访问文件可能会泄漏文件系统中的敏感信息

可能存在跨域漏洞。在 WebView 中启用从 URL 访问文件可能会泄漏文件系统中的敏感信息
https://github.com/OWASP/owasp-mstg/blob/master/Document/0x05h-Testing-Platform-Interaction.md#static-analysis-6

Files:
com/braze/ui/inappmessage/views/InAppMessageHtmlBaseView.java, line(s) 126,121

中危安全漏洞 应用程序可以读取/写入外部存储器,任何应用程序都可以读取写入外部存储器的数据

应用程序可以读取/写入外部存储器,任何应用程序都可以读取写入外部存储器的数据
https://github.com/OWASP/owasp-mstg/blob/master/Document/0x05d-Testing-Data-Storage.md#external-storage

Files:
org/prebid/mobile/rendering/sdk/deviceData/managers/DeviceInfoImpl.java, line(s) 221
org/prebid/mobile/rendering/utils/helpers/Utils.java, line(s) 175

中危安全漏洞 此应用可能包含硬编码机密信息

从应用程序中识别出以下机密确保这些不是机密或私人信息
AdMob广告平台的=> "com.google.android.gms.ads.APPLICATION_ID" : "ca-app-pub-7724422677792634~3459119586"
凭证信息=> "com.google.android.geo.API_KEY" : "AIzaSyDQF6r79gCfYcBo2bRVOunGac_CrekUIHM"
"branded_trust_anonymous_user" : "DBA-bruger"
"com.google.firebase.crashlytics.mapping_file_id" : "67807c1d7bae47d984ba0c191ab7a77b"
"com_braze_image_is_read_tag_key" : "com_appboy_image_is_read_tag_key"
"com_braze_image_lru_cache_image_url_key" : "com_braze_image_lru_cache_image_url_key"
"com_braze_image_resize_tag_key" : "com_appboy_image_resize_tag_key"
"employment_sector_private" : "Privat"
"google_api_key" : "AIzaSyDQPKtBN3MLaT97_Rol1Kf_C9_EsaxnLVQ"
"google_app_id" : "1:944302596709:android:f962729ae7c5193e08dc8c"
"google_crash_reporting_api_key" : "AIzaSyDQPKtBN3MLaT97_Rol1Kf_C9_EsaxnLVQ"
"private_feedback_header_url" : "https://support.dba.dk/hc/da/articles/22730060500754"
"realestate_itempage_object_page_real_estate_key_info_cadastre_info" : "%1$s: %2$s"
"realestate_itempage_object_page_real_estate_key_info_cadastres_heading" : "Matrikkelinformation"
"realestate_itempage_object_page_real_estate_key_info_facilities_heading" : "Faciliteter"
"realestate_itempage_object_page_real_estate_key_info_sales_cost_heading" : "Salgsomkostninger"
"realestate_itempage_object_page_real_estate_key_info_size_description_heading" : "Arealbeskrivelse"
"user" : "Brugerprofil"
3757180025770020463545507224491183603594455134769762486694567779615544477440556316691234405012945539562144444537289428522585666729196580810124344277578376784
0f9e6a9a-fc1d-4cd6-b730-df5a089e8026
34cc08f5-c73c-4ca9-b8a4-dbdeaaa0944b
115792089210356248762697446949407573529996955224135760342422259061068512044369
115792089210356248762697446949407573530086143415290314195533631308867097853951
66ed42541519eb061111df09
6864797660130609714981900799081393217269435300143305409394463459185543183397656052122559640661454554977296311391480858037121987999716643812574028291115057148
258EAFA5-E914-47DA-95CA-C5AB0DC85B11
9b6c11c3b9d310dbf7f9bf46243c9d6b
115792089237316195423570985008687907853269984665640564039457584007908834671663
6079834b9b0b741812e7e91f
41808837-4c97-49d3-bff4-042bd4409795
39402006196394479212279040100143613805079739270465446667948293404245721771496870329047266088258938001861606973112316
41058363725152142129326129780047268409114441015993725554835256314039467401291
32670510020758816978083085130507043184471273380659243275938904335757337482424
de06eb1d61ddfee87850bbf894121aee
4faa4ed0efd04b1a73000003
5087dc1b421c7a0b79000000
6864797660130609714981900799081393217269435300143305409394463459185543183397655394245057746333217197532963996371363321113864768612440380340372808892707005449
6864797660130609714981900799081393217269435300143305409394463459185543183397656052122559640661454554977296311391480858037121987999716643812574028291115057151
6182715aeb8a2840201923df
001a6ea0-1452-11f0-85f3-09a30aa53c4d
312f07c1-fd85-4085-a998-c99358d62fa4
5b6a8a93-6665-425c-af65-de10d5c09ece
442f4880-6f9c-11ef-a394-ff9599a06f83
D6F2E73B-9C5D-454D-9A9B-3FD8ABF9E909
1093849038073734274511112390766805569936207598951683748994586394495953116150735016013708737573759623248592132296706313309438452531591012912142327488478985984
a85106150b1659a79994fc6333064e87
67b843971b099b0edf179d70
61b1cad46cc9747bb32a4109
36134250956749795798585127919587881956611106672985015071877198253568414405109
0425be20-1452-11f0-990c-ed832b600b1c
27580193559959705877849011840389048093056905856361568521428707301988689241309860865136260764883745107765439761230575
618270b33786d16a8e56cb6f
66ed42541519eb061111df23
2bfc4dd553b47c0933713e2ae090855b
6756b71ec2cefdba0c186bc69f0d490e
37a6259cc0c1dae299a7866489dff0bd
8322077b5d6270f4a424de9f530e765f
e10a04ab5a77cf26f204272232f8fdb3
642aae64a087ba18debec91b
650421cf50eeae31ecd2a2d3
0a132fb0-1452-11f0-9416-091e933a1a85
-1668651148000-fc6c6eb12aa0
26247035095799689268623156744566981891852923491109213387815615900925518854738050089022388053975719786650872476732087
e9c7fa1c-06b1-442b-a5ab-21ac5e4004e0
fd46585b-9e55-444f-8b91-2fac85b9f792
57dba1b72fdeecf70a4a42e195b00f25
6076b1fcff301a1b179f0ebf
MwVjAJSxLzLgBGRjZv00Amt5YGuyLGtgLGVlBQt3A2WwLzVk
a65f6914-3b49-4efc-a173-2d530a9f0b14
60dacc2730125558546091ca
66ed42541519eb061111df18
bc8dfec6-dbae-40f0-9acd-3d244e6e0e9a
2dbec8c8-8924-4f40-a11e-d7afaef9ae49
-1570612861542-284f4c12e75f
619b4fc0dae2234905e4a187
b3aa572d03811249e1dcda6cd1d2e32c
cc4ae640-f99b-11ef-a4d2-fd8870144caa
8325710961489029985546751289520108179287853048861315594709205902480503199884419224438643760392947333078086511627871
66c5e7ee560c9f32a47dbe39
666af5fd92c5e50b58f102b8
115792089237316195423570985008687907852837564279074904382605163141518161494337
61926e5b3786d16a8e56cb79
b6bd7736-5cce-4d6f-be24-edd66b68f6d6
3f2292fc-48ce-4f7d-9a23-43ef6d953426
55066263022277343669578718895168534326250603453777594175500187360389116729240
66ed6e884b5d4e073bdde88e
115792089210356248762697446949407573530086143415290314195533631308867097853948
0fbab781-c5be-463b-b048-7407f70090a8
39402006196394479212279040100143613805079739270465446667946905279627659399113263569398956308152294913554433653942643
m1243validateVoucherBWLJW6A
-1613431812949-77b3351bb23d
19fb80c3-559a-4e26-b3d6-601a9898ed2a
48439561293906451759052585252797914202762949526041747995844080717082404635286
39402006196394479212279040100143613805079739270465446667948293404245721771496870329047266088258938001861606973112319
cae82997040d3f4fdbde1c3f2ecbfe3e
2661740802050217063228768716723360960729859168756973147706671368418802944996427808491545080627771902352094241225065558662157113545570916814161637315895999846
bca7b2cc-48ae-4815-8e83-de6fc6f08ce9
mo1249validateVoucherBWLJW6A
680f71d5c7b4122547861e44

安全提示信息 应用程序记录日志信息,不得记录敏感信息

应用程序记录日志信息,不得记录敏感信息
https://github.com/OWASP/owasp-mstg/blob/master/Document/0x05d-Testing-Data-Storage.md#logs

Files:
co/touchlab/kermit/CommonWriter.java, line(s) 35
co/touchlab/kermit/LogcatWriter.java, line(s) 82,103,91,112,85,106,79,100,88,94,109,115
com/adnuntius/android/sdk/Logger.java, line(s) 47
com/braze/support/BrazeLogger.java, line(s) 433,436,454,442,445,471,473,451,460,463
com/example/hybrid/webview/InternalWebView$setupServiceWorker$1.java, line(s) 19
com/example/hybrid/webview/InternalWebView.java, line(s) 86,142
com/iab/omid/library/prebidorg/utils/d.java, line(s) 18,11
com/schibsted/nmp/NmpActivityViewModel.java, line(s) 153
com/schibsted/nmp/NmpApplication.java, line(s) 247
com/schibsted/nmp/NmpApplicationLifecycleLogger.java, line(s) 24,30,36,42,48,55,62,70,79
com/schibsted/nmp/NmpNavigator.java, line(s) 197,201,316,321
com/schibsted/nmp/android/hybrid/NMPHybridViewKt.java, line(s) 67,118
com/schibsted/nmp/android/log/NmpLog.java, line(s) 148,149,387
com/schibsted/nmp/android/log/NmpLogWrapper.java, line(s) 20,14
com/schibsted/nmp/companyprofile/BrandProfileView.java, line(s) 616
com/schibsted/nmp/companyprofile/contact/BrandProfileContactPresenter.java, line(s) 208,345
com/schibsted/nmp/companyprofile/extendedProfile/ExtendedProfileLegacyKt$realtorProfileState$1$1.java, line(s) 115
com/schibsted/nmp/deeplinks/DebugIntentHandler.java, line(s) 49
com/schibsted/nmp/deeplinks/IntentHandler.java, line(s) 27
com/schibsted/nmp/foundation/adinput/ad/editor/widget/WidgetUtils.java, line(s) 197,191
com/schibsted/nmp/foundation/adinput/ad/service/AdInputEditor.java, line(s) 557,130,339,360,381,502,523,535,544
com/schibsted/nmp/foundation/adinput/ad/service/AdInputEditorRepository.java, line(s) 114,129,255,83
com/schibsted/nmp/foundation/adinput/confirmation/AdInputConfirmationPresenter$loadAdConfirmation$2$adConfirmationResponse$1.java, line(s) 60,69
com/schibsted/nmp/foundation/adinput/confirmation/AdInputConfirmationPresenter$loadAdConfirmation$2$trackingInfo$1.java, line(s) 67,75
com/schibsted/nmp/foundation/adinput/navigation/JetpackNavigatorKt.java, line(s) 19
com/schibsted/nmp/foundation/advertising/banners/GoogleAdManagerConfig$initGoogleAdManager$1.java, line(s) 59
com/schibsted/nmp/foundation/advertising/banners/ui/GoogleBanner$load$2$keywordsDeferred$1.java, line(s) 64
com/schibsted/nmp/foundation/advertising/banners/ui/GoogleBanner.java, line(s) 392
com/schibsted/nmp/foundation/advertising/contentmarketing/ui/ContentMarketingWebViewContainer.java, line(s) 250,252
com/schibsted/nmp/foundation/advertising/prebid/PrebidConfig.java, line(s) 225,237,240,212,233,333
com/schibsted/nmp/foundation/search/data/SearchRepository$createBannerConfigurationRequest$1.java, line(s) 73,85
com/schibsted/nmp/foundation/search/data/SearchRepository.java, line(s) 84,134
com/schibsted/nmp/foundation/search/resultpage/DefaultFeedbackHandler.java, line(s) 331
com/schibsted/nmp/foundation/search/resultpage/SearchResultPageContainerView.java, line(s) 341
com/schibsted/nmp/job/itempage/AdConfig.java, line(s) 31
com/schibsted/nmp/job/itempage/CompositeResultUseCase.java, line(s) 50
com/schibsted/nmp/job/itempage/JobItemPagePresenter$load$1$1.java, line(s) 76
com/schibsted/nmp/job/search/container/JobResultPageContainerView.java, line(s) 318
com/schibsted/nmp/job/search/container/fragment/JobSearchContainerFragment.java, line(s) 315,334,354
com/schibsted/nmp/job/search/container/fragment/JobSearchFragment.java, line(s) 249
com/schibsted/nmp/job/search/resultpage/JobSearchAdapter.java, line(s) 281
com/schibsted/nmp/job/search/resultpage/JobSearchPagePresenter.java, line(s) 350
com/schibsted/nmp/job/search/resultpage/JobSearchPageView.java, line(s) 801
com/schibsted/nmp/job/search/smartsearch/viewmodel/JobSmartSearchViewModel$generateAISummary$1.java, line(s) 73
com/schibsted/nmp/job/search/sort/JobSortType.java, line(s) 259
com/schibsted/nmp/kyc/BankVerificationFragment.java, line(s) 202
com/schibsted/nmp/kyc/KycEidVerifyFragment.java, line(s) 162
com/schibsted/nmp/kyc/KycStepOneFragment.java, line(s) 240
com/schibsted/nmp/kyc/KycViewModel$getBankingLink$1.java, line(s) 75
com/schibsted/nmp/kyc/KycViewModel$getEIdLink$1.java, line(s) 76
com/schibsted/nmp/kyc/KycViewModel$getEidAnnouncement$1.java, line(s) 78
com/schibsted/nmp/kyc/KycViewModel$getKycBankReport$1.java, line(s) 110
com/schibsted/nmp/kyc/KycViewModel$submitKycData$2.java, line(s) 86
com/schibsted/nmp/kyc/KycViewModel.java, line(s) 141,150,180
com/schibsted/nmp/kyc/compose/screens/BankVerificationViewKt.java, line(s) 211
com/schibsted/nmp/kyc/compose/screens/KycEidVerifyViewKt.java, line(s) 280,356,361
com/schibsted/nmp/mobility/adinput/managead/AdManagementPresenter.java, line(s) 627,450
com/schibsted/nmp/mobility/itempage/AdConfig.java, line(s) 31
com/schibsted/nmp/mobility/itempage/CommonAdLinksView.java, line(s) 133
com/schibsted/nmp/mobility/itempage/CompositeResultUseCase.java, line(s) 99
com/schibsted/nmp/mobility/itempage/MobilityItemPagePresenter$load$1$1.java, line(s) 76
com/schibsted/nmp/mobility/itempage/MobilityItemPagePresenter.java, line(s) 1813,1815,1817
com/schibsted/nmp/mobility/landingpage/MobilityLandingPageFragment.java, line(s) 328
com/schibsted/nmp/mobility/landingpage/MobilityLandingPageViewModel$loadData$1.java, line(s) 101
com/schibsted/nmp/mobility/search/container/MobilityResultPageContainerView.java, line(s) 318
com/schibsted/nmp/mobility/search/container/fragment/MobilitySearchContainerFragment.java, line(s) 317,336,356
com/schibsted/nmp/mobility/search/container/fragment/MobilitySearchFragment.java, line(s) 249
com/schibsted/nmp/mobility/search/resultpage/MobilitySearchAdapter.java, line(s) 289
com/schibsted/nmp/mobility/search/resultpage/MobilitySearchPagePresenter.java, line(s) 356
com/schibsted/nmp/mobility/search/resultpage/MobilitySearchPageView.java, line(s) 812
com/schibsted/nmp/mobility/search/sort/MobilitySortType.java, line(s) 665
com/schibsted/nmp/mobility/tjm/shared/webview/WebViewViewModel.java, line(s) 134,157,208
com/schibsted/nmp/navigation/NavigationLogger.java, line(s) 61
com/schibsted/nmp/notifications/NotificationDeeplinkHandlerKt.java, line(s) 20
com/schibsted/nmp/realestate/itempage/AdConfig.java, line(s) 69
com/schibsted/nmp/realestate/itempage/CompositeResultUseCase.java, line(s) 124
com/schibsted/nmp/realestate/itempage/RealestateItemPagePresenter$load$1$1.java, line(s) 76
com/schibsted/nmp/realestate/itempage/RealestateItemPagePresenter.java, line(s) 1442,1374,1565,1567,1569
com/schibsted/nmp/realestate/itempage/newconstruction/description/NewConstructionDescriptionPresenter.java, line(s) 108
com/schibsted/nmp/realestate/itempage/newconstruction/interestform/NewConstructionInterestFormPresenter.java, line(s) 215,228,270
com/schibsted/nmp/realestate/itempage/plugins/NeighborhoodPlugin.java, line(s) 125
com/schibsted/nmp/realestate/itempage/screens/RealEstateObjectPageFragmentNewOrigin.java, line(s) 214
com/schibsted/nmp/realestate/itempage/screens/RealEstateObjectPageLinks.java, line(s) 279
com/schibsted/nmp/realestate/search/container/RealEstateResultPageContainerView.java, line(s) 308
com/schibsted/nmp/realestate/search/container/fragment/RealEstateSearchContainerFragment.java, line(s) 322,341,361
com/schibsted/nmp/realestate/search/container/fragment/RealEstateSearchFragment.java, line(s) 257
com/schibsted/nmp/realestate/search/resultpage/RealEstateSearchAdapter.java, line(s) 288
com/schibsted/nmp/realestate/search/resultpage/RealEstateSearchPagePresenter.java, line(s) 319
com/schibsted/nmp/realestate/search/resultpage/RealEstateSearchPageView.java, line(s) 682
com/schibsted/nmp/realestate/search/sort/RealEstateSortType.java, line(s) 880
com/schibsted/nmp/recommerce/search/container/RecommerceResultPageContainerView.java, line(s) 309
com/schibsted/nmp/recommerce/search/container/fragment/RecommerceSearchContainerFragment.java, line(s) 326,345,365
com/schibsted/nmp/recommerce/search/results/RecommerceSearchAdapter.java, line(s) 364,460,676
com/schibsted/nmp/recommerce/search/results/RecommerceSearchFragment.java, line(s) 254
com/schibsted/nmp/recommerce/search/results/RecommerceSearchPagePresenter.java, line(s) 378
com/schibsted/nmp/recommerce/search/results/RecommerceSearchPageView.java, line(s) 769
com/schibsted/nmp/recommerce/search/semanticsearch/ui/compose/SemanticSearchScreenKt$SearchResultContent$2$1$1$4.java, line(s) 74
com/schibsted/nmp/recommerce/search/sort/RecommerceSortType.java, line(s) 335
com/schibsted/nmp/remoteconfig/FirebaseRemoteConfigController$fetchConfig$1.java, line(s) 55
com/schibsted/nmp/reviewmanager/BaseNmpReviewManager.java, line(s) 49,56,81,85,91,96
com/schibsted/nmp/savedsearchdata/repository/SavedSearchesRepository.java, line(s) 629,344,383,519,588,373,622
com/schibsted/nmp/savedsearches/SavedSearchesView.java, line(s) 255
com/schibsted/nmp/sharedobjectpage/ObjectPageLinks.java, line(s) 315
com/schibsted/nmp/sharedobjectpage/contactdialog/ContactFormViewKt.java, line(s) 277
com/schibsted/nmp/trust/feedback/output/privatelisting/PrivateFeedbackFragment.java, line(s) 320
com/schibsted/nmp/trust/service/auth/TrustApiAuthenticator.java, line(s) 40
com/schibsted/nmp/trust/service/auth/TrustAuthInterceptor.java, line(s) 40
com/schibsted/nmp/warp/components/WarpAlertKt.java, line(s) 194,204,213,223,232,241
com/schibsted/nmp/warp/components/WarpBoxKt.java, line(s) 124,134,144,153
com/schibsted/pulse/android/unicorn/mvvm/event/SingleLiveEvent.java, line(s) 28
com/schibsted/pulse/android/unicorn/network/model/converter/PulseEventResponseConverter.java, line(s) 45,57,80,91
com/schibsted/pulse/tracker/PulseTrackerImpl.java, line(s) 88
com/schibsted/pulse/tracker/environment/PulseEnvironment.java, line(s) 548
com/schibsted/pulse/tracker/internal/config/ConfigurationConverter.java, line(s) 80
com/schibsted/pulse/tracker/internal/config/ConfigurationManager.java, line(s) 52
com/schibsted/pulse/tracker/internal/config/ConfigurationServiceWrapper.java, line(s) 46
com/schibsted/pulse/tracker/internal/consents/client/ConsentsClient.java, line(s) 54
com/schibsted/pulse/tracker/internal/event/dispatcher/DispatchManager.java, line(s) 63
com/schibsted/pulse/tracker/internal/identity/manager/CisIdentityDataManager.java, line(s) 51,62,65
com/schibsted/pulse/tracker/internal/identity/manager/CisRefreshManager.java, line(s) 62
com/schibsted/pulse/tracker/internal/identity/manager/CisServiceWrapper.java, line(s) 45,58
com/schibsted/pulse/tracker/internal/identity/manager/IdentificationManager.java, line(s) 63
com/schibsted/pulse/tracker/internal/network/NetworkDiModule.java, line(s) 189
com/schibsted/pulse/tracker/internal/repository/CleanerDao.java, line(s) 31
com/schibsted/pulse/tracker/internal/repository/InMemoryPulseDatabaseProvider.java, line(s) 36
com/schibsted/pulse/tracker/internal/user/UserManager.java, line(s) 10,17
com/schibsted/pulse/tracker/internal/utils/HashUtils.java, line(s) 15,21
com/schibsted/pulse/unicorn/android/ui/custom/jsonpreview/JsonPreviewView.java, line(s) 109
com/slack/api/model/IntegrationLog.java, line(s) 41
com/zaxxer/hikari/util/JavassistProxyFactory.java, line(s) 49,60,96
io/github/aakira/napier/DebugAntilog.java, line(s) 70,88
io/glimr/sdk/audience/GLAudienceManager.java, line(s) 40,73
io/glimr/sdk/engine/GLManager.java, line(s) 164,171,181,205,209,214,225,234,237,242,250,111,147,175,186,191
io/glimr/sdk/network/GLEndPoints.java, line(s) 21
io/glimr/sdk/network/GLPostReqAsync.java, line(s) 75,79,101
io/glimr/sdk/network/GLRequestPayload.java, line(s) 118,140,149,160,174,186
io/ktor/client/plugins/logging/SimpleLogger.java, line(s) 12
io/ktor/http/parsing/DebugKt.java, line(s) 92
io/ktor/util/CoroutinesUtilsKt.java, line(s) 28,34
io/refiner/Refiner.java, line(s) 361,198
junit/runner/BaseTestRunner.java, line(s) 149
junit/runner/Version.java, line(s) 9
junit/textui/TestRunner.java, line(s) 88,112,137
no/finn/adinput/managead/AdManagementPresenter.java, line(s) 641,464
no/finn/android/ABTesting.java, line(s) 186,217
no/finn/android/FeatureToggles.java, line(s) 199
no/finn/android/UnleashController.java, line(s) 112,123
no/finn/android/appversion/AppVersion.java, line(s) 94
no/finn/android/auth/Account.java, line(s) 409,412,413,451,444,523,599,765,774,925,437
no/finn/android/auth/Auth.java, line(s) 124
no/finn/android/auth/AuthenticatedWebView.java, line(s) 113,121,123,137,70,127,132
no/finn/android/auth/FinnLogOutInterceptor.java, line(s) 95
no/finn/android/auth/FinnWebView.java, line(s) 51
no/finn/android/auth/LogoutDialog.java, line(s) 92
no/finn/android/candidateprofile/autocomplete/AutoCompleteViewModel$getAutocompleteData$1.java, line(s) 73
no/finn/android/candidateprofile/autocomplete/AutoCompleteViewModel$getLocationsSuggestion$1.java, line(s) 76
no/finn/android/candidateprofile/autocomplete/AutoCompleteViewModel$getPreferredSkills$1.java, line(s) 71
no/finn/android/candidateprofile/autocomplete/AutoCompleteViewModel$getSkillsSuggestions$1.java, line(s) 79
no/finn/android/candidateprofile/common/chips/SuggestionsChipPresenter.java, line(s) 153,231
no/finn/android/candidateprofile/jobprofile/JobProfileViewModel$getProfileData$1.java, line(s) 81
no/finn/android/candidateprofile/jobprofile/JobProfileViewModel$getProfileSettings$1.java, line(s) 75
no/finn/android/candidateprofile/jobprofile/JobProfileViewModel$updateEmailToggle$1.java, line(s) 68
no/finn/android/candidateprofile/jobprofile/cv/JobProfileComponentsViewModel$addEducation$1.java, line(s) 69
no/finn/android/candidateprofile/jobprofile/cv/JobProfileComponentsViewModel$addEmployment$1.java, line(s) 69
no/finn/android/candidateprofile/jobprofile/cv/JobProfileComponentsViewModel$addLanguage$1.java, line(s) 68
no/finn/android/candidateprofile/jobprofile/cv/JobProfileComponentsViewModel$deleteEducation$1.java, line(s) 68
no/finn/android/candidateprofile/jobprofile/cv/JobProfileComponentsViewModel$deleteEmployment$1.java, line(s) 68
no/finn/android/candidateprofile/jobprofile/cv/JobProfileComponentsViewModel$deleteFile$1.java, line(s) 67
no/finn/android/candidateprofile/jobprofile/cv/JobProfileComponentsViewModel$deleteLanguage$1.java, line(s) 68
no/finn/android/candidateprofile/jobprofile/cv/JobProfileComponentsViewModel$deleteNextRole$1.java, line(s) 64
no/finn/android/candidateprofile/jobprofile/cv/JobProfileComponentsViewModel$getEducationLevels$1.java, line(s) 69
no/finn/android/candidateprofile/jobprofile/cv/JobProfileComponentsViewModel$getLanguages$1.java, line(s) 70
no/finn/android/candidateprofile/jobprofile/cv/JobProfileComponentsViewModel$getLocationsSuggestion$1.java, line(s) 73
no/finn/android/candidateprofile/jobprofile/cv/JobProfileComponentsViewModel$getSkillsSuggestions$1.java, line(s) 75
no/finn/android/candidateprofile/jobprofile/cv/JobProfileComponentsViewModel$prepareAndDownloadFile$1.java, line(s) 72
no/finn/android/candidateprofile/jobprofile/cv/JobProfileComponentsViewModel$prepareAndUploadFile$1.java, line(s) 91
no/finn/android/candidateprofile/jobprofile/cv/JobProfileComponentsViewModel$saveLocations$1.java, line(s) 69
no/finn/android/candidateprofile/jobprofile/cv/JobProfileComponentsViewModel$savePreferredRolesAndTypes$1.java, line(s) 71
no/finn/android/candidateprofile/jobprofile/cv/JobProfileComponentsViewModel$saveSkills$1.java, line(s) 69
no/finn/android/candidateprofile/jobprofile/cv/JobProfileComponentsViewModel$updateBio$1.java, line(s) 68
no/finn/android/candidateprofile/jobprofile/cv/JobProfileComponentsViewModel$updateEducationDetails$1.java, line(s) 69
no/finn/android/candidateprofile/jobprofile/cv/JobProfileComponentsViewModel$updateEmployment$1.java, line(s) 69
no/finn/android/candidateprofile/jobprofile/cv/JobProfileComponentsViewModel$updateLanguage$1.java, line(s) 68
no/finn/android/candidateprofile/jobprofile/cv/JobProfileComponentsViewModel$updatePersonalDetails$1.java, line(s) 74
no/finn/android/candidateprofile/jobprofile/salary/JobProfileSalaryViewModel$deleteSalary$1.java, line(s) 70
no/finn/android/candidateprofile/jobprofile/salary/JobProfileSalaryViewModel$getProfileData$1.java, line(s) 71
no/finn/android/candidateprofile/legacy/autocomplete/autocomplete/GenericAutocompletePresenter.java, line(s) 258,382
no/finn/android/candidateprofile/legacy/education/EducationLevelChipPresenter.java, line(s) 138
no/finn/android/candidateprofile/marketfront/JobMarketFrontViewModel$generateAISummary$1.java, line(s) 73
no/finn/android/candidateprofile/marketfront/JobMarketFrontViewModel$getExistingProfileData$1.java, line(s) 93
no/finn/android/candidateprofile/marketfront/JobMarketFrontViewModel$getExistingUserProfileData$1.java, line(s) 72
no/finn/android/candidateprofile/marketfront/JobMarketFrontViewModel$getProfileSettings$1.java, line(s) 76
no/finn/android/candidateprofile/marketfront/JobMarketFrontViewModel$getTotalAmountOfAds$1.java, line(s) 71
no/finn/android/candidateprofile/marketfront/JobMarketFrontViewModel$savePersonalDetails$1.java, line(s) 79
no/finn/android/candidateprofile/marketfront/JobMarketFrontViewModel$updateEmailToggle$1.java, line(s) 69
no/finn/android/candidateprofile/onboarding/education/EducationViewModel$getEducationLevels$1.java, line(s) 71
no/finn/android/candidateprofile/onboarding/education/EducationViewModel$getExistingProfileData$1.java, line(s) 80
no/finn/android/candidateprofile/onboarding/education/EducationViewModel$handleEducationChange$1.java, line(s) 97
no/finn/android/candidateprofile/onboarding/employment/EmploymentViewModel$addEmployment$1.java, line(s) 77
no/finn/android/candidateprofile/onboarding/employment/EmploymentViewModel$updateEmployment$1.java, line(s) 77
no/finn/android/candidateprofile/onboarding/location/LocationViewModel$getExistingProfileData$1.java, line(s) 85
no/finn/android/candidateprofile/onboarding/location/LocationViewModel$saveLocation$1.java, line(s) 78
no/finn/android/candidateprofile/onboarding/nextrole/NextRoleViewModel$activateProfile$1.java, line(s) 70
no/finn/android/candidateprofile/onboarding/nextrole/NextRoleViewModel$saveLocation$1.java, line(s) 77
no/finn/android/candidateprofile/onboarding/nextrole/NextRoleViewModel$savePreferredRolesAndTypes$1.java, line(s) 82
no/finn/android/candidateprofile/onboarding/nextrole/NextRoleViewModel$updateEmailToggle$1.java, line(s) 68
no/finn/android/candidateprofile/onboarding/worksituation/WorkSituationViewModel.java, line(s) 237,288,345
no/finn/android/candidateprofile/profile/JobProfilePresenter.java, line(s) 477,542,607,674,749,814,872,930,989,1046,1104,1162,1227,1292,1357,1426,1489,1574
no/finn/android/candidateprofile/profile/edit/EmailNotificationTogglePresenter.java, line(s) 113
no/finn/android/candidateprofile/profile/educationhistory/EducationHistoryViewModel.java, line(s) 128,178,189,238,249,297,308
no/finn/android/candidateprofile/profile/jobhistory/JobHistoryViewModel.java, line(s) 127,177,188,237,248,296,307
no/finn/android/candidateprofile/salary/employment/SalaryEmploymentViewModel$getExistingProfileData$1.java, line(s) 72,86
no/finn/android/candidateprofile/salary/jobprofilecheck/JobProfileCheckViewModel$getExistingProfileData$1.java, line(s) 80
no/finn/android/candidateprofile/salary/jobprofilecheck/JobProfileCheckViewModel$savePersonalDetails$1.java, line(s) 79,93
no/finn/android/candidateprofile/salary/landing/SalaryLandingViewModel$getExistingProfileData$1.java, line(s) 76,89
no/finn/android/candidateprofile/salary/salaryinfo/SalaryInfoViewModel$getExistingProfileData$1.java, line(s) 99,114
no/finn/android/consent/ConsentsImpl.java, line(s) 113
no/finn/android/favorites/DeleteFavoriteFolder.java, line(s) 102,88
no/finn/android/favorites/FavoritesPresenter.java, line(s) 785,368,563,689,889,954,1120
no/finn/android/favorites/ShareFavorites.java, line(s) 156,163
no/finn/android/favorites/favoritefolder/FavoritesFolderViewModel.java, line(s) 250,311,410,450,233,371
no/finn/android/favorites/favoritesold/FavoriteSoldViewModel.java, line(s) 168
no/finn/android/favorites/view/ItemNoteBottomSheet.java, line(s) 296
no/finn/android/networking/CacheControl.java, line(s) 130,142,69
no/finn/android/networking/CacheDeborkifier.java, line(s) 56,81,50,51,86,87,93
no/finn/android/notifications/NotificationCountProviderImpl.java, line(s) 120
no/finn/android/notifications/NotificationsController.java, line(s) 203
no/finn/android/notifications/fcm/FCMMessagingService.java, line(s) 192,128,137,147,154
no/finn/android/notifications/push/SaveFavouriteReceiver$onReceive$1.java, line(s) 65,77
no/finn/android/notifications/push/SaveFavouriteReceiver.java, line(s) 168
no/finn/android/notifications/util/NotificationImageUtilKt.java, line(s) 67,136
no/finn/android/profile/publicprofile/FinnTrustSummaryKt$FinnTrustSummary$1.java, line(s) 52
no/finn/android/profile/verifieduser/VerifyUserPresenter.java, line(s) 137
no/finn/android/profile/verifieduser/VerifyUserView.java, line(s) 161,166,207,209,214,219,224,229
no/finn/android/recommendations/DiscoverPresenter.java, line(s) 498
no/finn/android/sdk/ImageCDNUtil.java, line(s) 103
no/finn/android/sdk/ImageCacheController.java, line(s) 23,28
no/finn/android/togglefavorites/bottomsheet/AddToFavoritesBottomSheet.java, line(s) 143,263
no/finn/android/track/FinnEventCollector.java, line(s) 83,149,191,197
no/finn/android/track/PulseTrackerHelper.java, line(s) 77
no/finn/android/track/PulseVerticalHelper.java, line(s) 785,862
no/finn/android/track/RefinerHelper.java, line(s) 116,124,160,105
no/finn/android/track/pulse/PulseEnvironmentId.java, line(s) 87,130
no/finn/android/ui/globalsearch/GlobalSearchViewModel.java, line(s) 349,394
no/finn/android/ui/globalsearch/newfrontier/api/NewFrontierResultKt.java, line(s) 69
no/finn/android/util/crashes/CrashReportingDelegate.java, line(s) 66
no/finn/android/util/crashes/outofmemory/MemoryDump.java, line(s) 18,19,20,21,23
no/finn/android/util/crashes/outofmemory/MemoryLeakTracker.java, line(s) 106
no/finn/androidprivacy/consent/ConsentManagerImpl$syncCategoryIDs$1.java, line(s) 74
no/finn/androidprivacy/consent/ConsentStoreImpl.java, line(s) 190
no/finn/androidprivacy/consent/SpClientEventController.java, line(s) 104,110,115
no/finn/authdata/SpidInfo.java, line(s) 93,115,135,139,143
no/finn/bap/viewmodel/RecommerceViewModel$getAdvertisingConfig$1.java, line(s) 86
no/finn/bap/viewmodel/RecommerceViewModel.java, line(s) 1231
no/finn/bottomsheetfilter/filters/FinnGeoFilterConfig.java, line(s) 430
no/finn/bottomsheetfilter/wrapper/BottomFilterWrapperPresenter.java, line(s) 558,587,692,809,874,964,1065,1078,1201,1375
no/finn/braze/BrazeRegistrarFactory.java, line(s) 49
no/finn/braze/FinnBrazeRegistrar.java, line(s) 61
no/finn/camera/FinnCameraKt$FinnCameraPreview$1.java, line(s) 142
no/finn/camera/utils/CameraUtilsKt.java, line(s) 74,64
no/finn/charcoal/controllers/selection/LocationPersistenceManager.java, line(s) 66,104,131
no/finn/charcoal/controllers/selection/URLToSelectionTranslatorKt.java, line(s) 135
no/finn/charcoal/ui/filter/geofilter/GeoSelectionMapView.java, line(s) 419
no/finn/dbcommon/DbHelper.java, line(s) 83
no/finn/favorites/data/FavoritesQueryHandler.java, line(s) 163,382,435
no/finn/favorites/ui/AddToFavoritesButton.java, line(s) 230
no/finn/favorites/ui/LargeAddToFavoritesButton.java, line(s) 218,251
no/finn/fcm/data/FCMDeviceHandler.java, line(s) 272,316,169,237,240,282,321
no/finn/jobapply/ui/components/JobTermsAndConditionsViewKt.java, line(s) 369
no/finn/legacyimageview/imageview/FinnImageView.java, line(s) 457
no/finn/legacytext/text/SamsungMitigatingTextView.java, line(s) 96,132
no/finn/map/FinnTileFetcher.java, line(s) 79
no/finn/messaging/notification/MessagingNotificationHelper.java, line(s) 108
no/finn/messaging/ui/MessagingContainerFragment.java, line(s) 248
no/finn/messaging/ui/MessagingTrackingHelper.java, line(s) 125,148
no/finn/mosaic/Placeholder.java, line(s) 94
no/finn/mypage/DebugView.java, line(s) 200,176
no/finn/mypage/MyPagePresenter.java, line(s) 242
no/finn/mypage/MyPageRepository.java, line(s) 109
no/finn/mypage/settings/NotificationSettingsPresenter.java, line(s) 469,675,235,294
no/finn/mypage/settings/PrivacySettingsViewModelImpl.java, line(s) 283,337,393,643,725,779,878,898,968,988
no/finn/mypage/settings/follow/FollowSettingsFragment$onCreateView$1$1.java, line(s) 93
no/finn/nmpmessaging/components/LinkifyTextKt.java, line(s) 93
no/finn/nmpmessaging/conversation/ConversationReplyBarKt$ReplyBar$2$1$1$1.java, line(s) 57,94
no/finn/nmpmessaging/conversation/ConversationReplyBarKt.java, line(s) 447
no/finn/nmpmessaging/conversation/ConversationViewModel$setConversationAsRead$1.java, line(s) 56
no/finn/nmpmessaging/conversation/ConversationViewModel.java, line(s) 297,563
no/finn/nmpmessaging/data/DefaultRealTimeMessagingDataSource.java, line(s) 136,138
no/finn/notificationcenter/NotificationDetailPresenter.java, line(s) 374
no/finn/notificationcenter/NotificationDetailView.java, line(s) 266
no/finn/notificationcenter/NotificationsCenterPresenter.java, line(s) 1114
no/finn/notificationcenter/NotificationsCenterView.java, line(s) 450
no/finn/poimap/PoiMapPresenter.java, line(s) 207
no/finn/realestate/blink/BlinkView.java, line(s) 229,237
no/finn/realestate/loancalculator/LoanCalculatorView.java, line(s) 385
no/finn/recommerce/adinput/confirmation/RecommerceAdInputConfirmationPresenter$loadAdConfirmation$2$adConfirmationResponse$1.java, line(s) 62,71
no/finn/recommerce/adinput/confirmation/RecommerceAdInputConfirmationPresenter$loadAdConfirmation$2$trackingInfo$1.java, line(s) 71,79
no/finn/recommerce/adinput/managead/AdManagementPresenter.java, line(s) 621,444
no/finn/recommerce/camera/usecases/GetWelcomeMessageUseCase$getWelcomeMessage$2.java, line(s) 64
no/finn/recommerce/photoupload/RecommerceAddPhotosFragment.java, line(s) 48
no/finn/recyclerview/LegacyRecyclerView.java, line(s) 308,137,168
no/finn/reportad/ReportAdHybridFragment.java, line(s) 142
no/finn/searchdata/lastsearches/LastSearchesQueryHandler.java, line(s) 127
no/finn/searchdata/motorpromo/MotorPromoRepository$loadMotorPromo$1.java, line(s) 74
no/finn/stories/MuteStoriesRepositoryImpl.java, line(s) 27,36,43,52
no/finn/stories/StoriesRepositoryImpl.java, line(s) 84
no/finn/toolbar/SearchView.java, line(s) 130
no/finn/transactiontorget/AttachmentHelper.java, line(s) 93,96,99
no/finn/transactiontorget/UtilsKt.java, line(s) 49
no/finn/transactiontorget/acceptoffer/AcceptOfferPresenter.java, line(s) 166,256
no/finn/transactiontorget/acceptoffer/AcceptOfferView.java, line(s) 513
no/finn/transactiontorget/buyerbiddetails/BuyerStatusViewModel$commitTransactionPayment$1.java, line(s) 114
no/finn/transactiontorget/buyerbiddetails/BuyerStatusViewModel$confirmDelivery$1.java, line(s) 75
no/finn/transactiontorget/buyerbiddetails/BuyerStatusViewModel.java, line(s) 250
no/finn/transactiontorget/disputev3/DisputeViewModel$uploadAttachments$1.java, line(s) 124
no/finn/transactiontorget/disputev3/DisputeViewModel.java, line(s) 480,523,567,609,672,737,805,854,917,968
no/finn/transactiontorget/selleraddetails/SellerStatusViewModel$declineOffer$1.java, line(s) 83
no/finn/transactiontorget/selleraddetails/SellerStatusViewModel$getCancelTransactionResponse$1.java, line(s) 75
no/finn/transactiontorget/transactionsoverview/MyTransactionViewModel$loadData$1.java, line(s) 86
no/finn/transactiontorget/transactionsoverview/MyTransactionsPresenter.java, line(s) 164
no/finn/trustcomponent/ui/FeedbackInputFragment.java, line(s) 197
no/finn/ui/components/avatar/AvatarView.java, line(s) 134
no/finn/ui/components/avatar/AvatarViewModel.java, line(s) 221,275
no/finn/ui/components/button/FinnDrawableButton.java, line(s) 69
org/koin/android/logger/AndroidLogger.java, line(s) 61,71,73,65,69
org/prebid/mobile/LogUtil.java, line(s) 124
org/prebid/mobile/PrebidMobile.java, line(s) 230
org/prebid/mobile/PrebidNativeAd.java, line(s) 292
org/prebid/mobile/rendering/mraid/methods/MraidResize.java, line(s) 368
org/prebid/mobile/rendering/sdk/deviceData/managers/DeviceInfoImpl.java, line(s) 187
org/prebid/mobile/rendering/utils/helpers/ExternalViewerUtils.java, line(s) 27,23
org/prebid/mobile/rendering/views/webview/AdWebView.java, line(s) 110
timber/log/Timber.java, line(s) 405,424
uk/co/senab/photoview/PhotoViewAttacher.java, line(s) 24
uk/co/senab/photoview/log/LoggerDefault.java, line(s) 18,23,48,53,28,33,8,13,38,43

安全提示信息 应用程序可以写入应用程序目录。敏感信息应加密

应用程序可以写入应用程序目录。敏感信息应加密


Files:
bo/content/b0.java, line(s) 376,376
bo/content/d6.java, line(s) 469
bo/content/e.java, line(s) 245,245
bo/content/f1.java, line(s) 174,177
bo/content/g6.java, line(s) 198
bo/content/h4.java, line(s) 68,68
bo/content/l0.java, line(s) 219,219
bo/content/l1.java, line(s) 103,103
bo/content/m.java, line(s) 348,351
bo/content/m0.java, line(s) 112,112
bo/content/m6.java, line(s) 278,281
bo/content/n0.java, line(s) 35,35
bo/content/r3.java, line(s) 78,78
bo/content/v5.java, line(s) 253,253
bo/content/w4.java, line(s) 37,37
bo/content/y0.java, line(s) 75
com/braze/configuration/RuntimeAppConfigurationProvider.java, line(s) 57,57
com/braze/managers/BrazeGeofenceManager.java, line(s) 744

安全提示信息 此应用程序将数据复制到剪贴板。敏感数据不应复制到剪贴板,因为其他应用程序可以访问它

此应用程序将数据复制到剪贴板。敏感数据不应复制到剪贴板,因为其他应用程序可以访问它
https://github.com/OWASP/owasp-mstg/blob/master/Document/0x04b-Mobile-App-Security-Testing.md#clipboard

Files:
com/schibsted/nmp/growth/rewardscenter/challengedetails/sections/RewardSectionKt.java, line(s) 4,642,643
com/schibsted/nmp/job/shared/utils/CopyTextToClipboardKt.java, line(s) 4,27,28
no/finn/about/AboutView.java, line(s) 4,268
no/finn/androidutils/ClipboardUtil.java, line(s) 4,28,24,30
no/finn/mypage/DebugView.java, line(s) 4,197

已通过安全项 此应用程序使用SSL Pinning 来检测或防止安全通信通道中的MITM攻击

此应用程序使用SSL Pinning 来检测或防止安全通信通道中的MITM攻击
https://github.com/OWASP/owasp-mstg/blob/master/Document/0x05g-Testing-Network-Communication.md#testing-custom-certificate-stores-and-certificate-pinning-mstg-network-4

Files:
com/m10s/identity/webflows/api/M10sIdentityApi.java, line(s) 36,36
com/schibsted/nmp/trust/injection/TrustDataModuleKt.java, line(s) 269,269
com/schibsted/pulse/android/unicorn/network/di/RetrofitDiModule.java, line(s) 31,37,31
com/schibsted/pulse/tracker/internal/config/ConfigurationDiModule.java, line(s) 130,130
com/schibsted/pulse/tracker/internal/event/dispatcher/DispatcherDiModule.java, line(s) 253,253
com/schibsted/pulse/tracker/internal/identity/manager/IdentificationDiModule.java, line(s) 173,173
no/finn/android/networking/NetworkModuleKt.java, line(s) 281,330
no/finn/mypage/DebugViewModel.java, line(s) 102,242,252
no/finntech/search/quest/SearchQuestClient.java, line(s) 69,70,82

已通过安全项 Firebase远程配置已禁用

Firebase远程配置URL ( https://firebaseremoteconfig.googleapis.com/v1/projects/944302596709/namespaces/firebase:fetch?key=AIzaSyDQPKtBN3MLaT97_Rol1Kf_C9_EsaxnLVQ ) 已禁用。响应内容如下所示:

响应码是 403

综合安全基线评分总结

应用图标

DBA v2506090350

Android APK
44
综合安全评分
中风险