JShelby233745 (Community Member) asked a question.

How can we avoid "Improper Export of Android Application Components"

The scan is reporting "Improper Export of Android Application Components" for the startup Activities in our apps. We are following the standard approach for configuring the Activity for the Launcher ("android.intent.category.LAUNCHER") and the app won't start if we set app specific permissions. Is there something else we should be doing?


65shutosh likes this.
  • Hi @JShelby233745 (Community Member)​ ,

     

    Thank you for your patience. I've contacted Veracode Research and was able to confirm that unfortunately at this time we do not automatically exempt activities with the Launcher category from being reported on for this category though as you mentioned there is no need to restrict this activity.

     

    Please propose a "Potential False Positive" mitigation on this in the Veracode Platform or through our IDE integrations, you can find more information on how to do this here: https://help.veracode.com/reader/DGHxSJy3Gn3gtuSIN2jkRQ/~p4MSKOS8F8X8h0KwFTKoQ . I would recommend adding a link to this community posting in the mitigation proposal.

    Afterwards, please contact your security team for approval for this proposal.

     

    Please let me know if you have any remaining questions or concerns.

     

    Thank you,

    Boy Baukema

    Expand Post
    Selected as Best
  • Hi @JShelby233745 (Community Member)​ ,

     

    Thank you for your question. I'm afraid I need to do a bit of research on this one, I'll get back to you as soon as possible.

     

    Thank you,

    Boy Baukema

    Expand Post
  • Hi @JShelby233745 (Community Member)​ ,

     

    Thank you for your patience. I've contacted Veracode Research and was able to confirm that unfortunately at this time we do not automatically exempt activities with the Launcher category from being reported on for this category though as you mentioned there is no need to restrict this activity.

     

    Please propose a "Potential False Positive" mitigation on this in the Veracode Platform or through our IDE integrations, you can find more information on how to do this here: https://help.veracode.com/reader/DGHxSJy3Gn3gtuSIN2jkRQ/~p4MSKOS8F8X8h0KwFTKoQ . I would recommend adding a link to this community posting in the mitigation proposal.

    Afterwards, please contact your security team for approval for this proposal.

     

    Please let me know if you have any remaining questions or concerns.

     

    Thank you,

    Boy Baukema

    Expand Post
    Selected as Best
    • JShelby233745 (Community Member)

      Thanks, we will mark this as a “Potential False Positive”, as you suggest.

      -JLS
  • 65shutosh (Community Member)

    Hi, is there any solution to this now?

  • Blomgren (Community Member)

    @Boy, Security Consultant (Veracode)​  We recently had a consultation call on this exact topic. Can you provide more detail if there are any specific cases where an instance of this flaw could be truly valid and exploitable when used in relation to app startup? If not, what is Veracode's position on making improvements to this test case by excluding to report the flaw when related to app startup? Have any improvements been considered or anything in-process currently?

    Expand Post

Topics (3)

No articles found
Loading

Ask the Community

Get answers, share a use case, discuss your favorite features, or get input from the community.