Deon
Posts: 0
Joined: Sun Jun 30, 2013 6:00 am

URGENT: Google Vulnerability Warding for outdated Cordova Library

HI

Google wants to unpublish my Apps. Please rectify ASAP. I see apps are using Ver Cordova 4.0.0 . Please fix this urgently!

Message from Google

This information is intended for developers of apps that utilize any version of Apache Cordova that precedes 4.1.1. These versions contain security vulnerabilities and are in violation of the Dangerous products provision of the Content Policy and section 4.4 of the Developer Distribution Agreement.

Please migrate your app(s) to Apache Cordova v.4.1.1 or higher as soon as possible and increment the version number of the upgraded APK. If you are using a 3rd party library that includes Apache Cordova, please notify the 3rd party and work with them to address the issue.

Deon
Posts: 0
Joined: Sun Jun 30, 2013 6:00 am

URGENT: Google Vulnerability Warding for outdated Cordova Library

Vulnerabilities and Remediation Deadlines

CVE-2015-5256; applies to pre-4.1.1 versions of Apache Cordova. These versions are vulnerable to improper application of whitelist restrictions on Android. This results in a vulnerability where whitelist restrictions are not properly applied. Improperly crafted URIs could be used to circumvent the whitelist, allowing for the execution of non-whitelisted Javascript. Beginning May 9, 2016, Google Play will block publishing of any new apps or updates that use pre-4.1.1 versions of Apache Cordova.
CVE-2015-1835; applies to pre-4.0.2 versions of Apache Cordova. These versions are vulnerable to remote exploit of secondary configuration variables in Apache Cordova on Android. Affected apps that don't have explicit values set in Config.xml can have undefined configuration variables set by Intent. This can cause unwanted dialogs appearing in applications and changes in the application behaviour that can include the app force-closing. Beginning May 9, 2016, Google Play will block publishing of any new apps or updates that use pre-4.1.1 versions of Apache Cordova.
CVE-2014-3502; applies to pre-3.5.1 versions of Apache Cordova. Vulnerabilities include a high severity cross-application scripting (XAS) vulnerability. Under certain circumstances, susceptible apps could be remotely exploited to steal sensitive information, such as user login credentials. The remediation deadline for this vulnerability has passed. Google Play will block publishing of any new apps or updates containing this vulnerability.

Ideal APP
Posts: 0
Joined: Thu Feb 11, 2016 12:18 pm

URGENT: Google Vulnerability Warding for outdated Cordova Library

I got this email from Google too !!!

Illya Stepanov
Posts: 0
Joined: Mon Mar 18, 2013 8:48 am

URGENT: Google Vulnerability Warding for outdated Cordova Library

Hi all -

We aware of this, please check the reply from Max here: https://getsatisfaction.com/apperyio/...

Return to “Issues”