Page 1 of 2

Security Alert: Apache Cordova vulnerabilities in your Google Play app

Posted: Wed Oct 01, 2014 9:43 pm
by Deon

Hi

I received this from Google today. Please advise urgently.

This is a notification that your io.appery.project110622, io.appery.project169710, io.appery.project170761, is built on a version of Apache Cordova that contains security vulnerabilities. This includes a high severity cross-application scripting (XAS) vulnerability. Under certain circumstances, vulnerable apps could be remotely exploited to steal sensitive information, such as user login credentials.
You should upgrade to Apache Cordova 3.5.1 or higher as soon as possible. For more information about the vulnerabilities, and for guidance on upgrading Apache Cordova, please see http://cordova.apache.org/announcemen....
Please note, applications with vulnerabilities that expose users to risk of compromise may be considered “dangerous products” and subject to removal from Google Play.
Regards,
Google Play Team
©2014 Google Inc.
1600 Amphitheatre Parkway
Mountain View, CA 94043


Security Alert: Apache Cordova vulnerabilities in your Google Play app

Posted: Wed Oct 01, 2014 10:23 pm
by Illya Stepanov

Hi Deon,

We are aware of this situation. It is planned to upgrade Cordova version in a nearest time.


Security Alert: Apache Cordova vulnerabilities in your Google Play app

Posted: Wed Oct 01, 2014 10:45 pm
by Deon

Thank you

I am not receiving any notifications regarding changes etc in appery or important updates.

Please can this be done?

Thanks


Security Alert: Apache Cordova vulnerabilities in your Google Play app

Posted: Wed Oct 01, 2014 11:00 pm
by Illya Stepanov

Could you please clarify what notifications do you mean?


Security Alert: Apache Cordova vulnerabilities in your Google Play app

Posted: Thu Oct 02, 2014 9:30 am
by Maryna Brodina

Hello!

Sorry, do you want to upgrade your app to the new builder?

http://devcenter.appery.io/documentat...


Security Alert: Apache Cordova vulnerabilities in your Google Play app

Posted: Thu Oct 02, 2014 9:43 am
by Deon

Will it fix the issue?


Security Alert: Apache Cordova vulnerabilities in your Google Play app

Posted: Thu Oct 02, 2014 11:09 am
by Maryna Brodina

No unfortunately. We are planning to update Cordova version in a few weeks.


Security Alert: Apache Cordova vulnerabilities in your Google Play app

Posted: Sat Jan 24, 2015 2:55 pm
by JorgeJones

I am receiving this error as well. Has the Cordova version been updated?


Security Alert: Apache Cordova vulnerabilities in your Google Play app

Posted: Sat Jan 24, 2015 3:33 pm
by Illya Stepanov

Hi - Could you please clarify what Libraries version you're using in your build?
:: http://devcenter.appery.io/documentat...


Security Alert: Apache Cordova vulnerabilities in your Google Play app

Posted: Sat Jan 24, 2015 6:27 pm
by JorgeJones

Ah, thanks. It was the default (v1.1), but I just updated to v2.1 and I expect that'll fix the issue.