Skip to content

Instantly share code, notes, and snippets.

@misterAnderson90
Created May 16, 2022 00:36
Show Gist options
  • Save misterAnderson90/7bb5d37b61d146b5bfbd5aaedf083548 to your computer and use it in GitHub Desktop.
Save misterAnderson90/7bb5d37b61d146b5bfbd5aaedf083548 to your computer and use it in GitHub Desktop.

CogniCrypt (report 1) for Hwloc-lstopo

  • Class: com.android.volley.InternalUtils

  • Method: sha1Hash

  • Line: 30

  • Issue details: ConstraintError

    • ConstraintError violating CrySL rule for java.security.MessageDigest.

    • First parameter (with value \SHA-1) should be any of {SHA-256, SHA-384, SHA-512}.

Code

  • Not available (the binary might have been obfuscated or have been written in Kotlin. Perhaps it resides in an external library).

Questions

  1. How likely might this warning reveal a security threat to this app?

  2. Are you likely to accept a patch that fixes this particular issue?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment