AFNetworking vulnerability

54 views
Skip to first unread message

chandra.s...@okta.com

unread,
Apr 27, 2015, 2:32:05 PM4/27/15
to res...@googlegroups.com
RestKit depends on very old version of AFNetworking. Is there a play to switch to the latest version any time soon?



chandra.s...@okta.com

unread,
May 5, 2015, 7:54:48 PM5/5/15
to res...@googlegroups.com
Anybody? When can we expect a version of RestKit that will work with latest version of AFNetworking?

Dan Morrow

unread,
May 7, 2015, 12:56:31 PM5/7/15
to res...@googlegroups.com
There's been discussion about moving RestKit to AFNetworking 2.x, and about how that would be an enormous undertaking. Some people have argued that RestKit would be better off using the new NSURLSession stuff, and dropping AFNetworking altogether. There may be someone working on an AFNetworking 2.x branch, but I'm not sure about that.

That said, is it known that this vuln is found in AFNetworking 1.x? Is it possible that it's just part of the 2.x line? I've been poking around, but haven't found anything definitive yet. 

PT

unread,
May 8, 2015, 8:32:14 PM5/8/15
to res...@googlegroups.com
See issue #2209 now closed. Vulnerability in AF 2.x not in 1.x so Restkit or other products using AF 1.x are fine. There has been some good progress on a Restkit version that can run either without AF or optionally alongside AF 2.x, some way to go as yet including review by the RK team, but very promising. The AF 2.x Restkit branch is not being worked on.

Chandra Shirashyad

unread,
May 13, 2015, 1:26:28 PM5/13/15
to res...@googlegroups.com
Thanks Dan and PT!

Is it possible to use just the mapping portion of Restkit? Essentially detach the networking layer so we can use anything to fetch the JSON object use RestKit for object mapping.

Thanks,
Chandra
Reply all
Reply to author
Forward
0 new messages