Hello ASAP developer,
Recently, we were made aware of a dependency confusion vulnerability when JitPack is used to resolve application dependencies. The applicability of the security risk depends on your application build configuration:
1. You include ASAP SDK in your application.
Note: We have 3 bundles
1. com.zoho.desk:asapsdk (This bundle is impacted)
2. com.zoho.desk:asap (No impact)
3. com.zoho.desk:asap-api (No impact)
2. If you have configured the JitPack repository in your dependency configuration at the top level before the mavenCentral() in your project’s build.gradle file, please follow the below mitigation steps.
Mitigation:
Kindly move the jitpack.io dependency to the bottom of the project's repositories and update the ASAP SDK (Android) to version 2.1.2 immediately.
If you have any questions, please write to us at support@zohodesk.com.
Writer is a powerful online word processor, designed for collaborative work.