You should upgrade to Apache Cordova 3.5.1 or higher??

0 favourites
  • I have a few apps that are published to google play using older versions of C2, google sent me an email today telling me that my apps had a security risk and could be taken down. ??

    any ideas? these are just childrens games, built with C2 only.

    THE EMAIL FROM GOOGLE

    This is a notification that your com.jameslimitlessdomains.com.balloons, com.jameslimitlessdomains.com.cb11, com.jameslimitlessdomains.com.f1app, com.jameslimitlessdomains.com.paint4, playstore.egg.surprise, who.built.the.ark.xdk, is built on a version of Apache Cordova that contains security vulnerabilities. This includes a high severity cross-application scripting (XAS) vulnerability. Under certain circumstances, vulnerable apps could be remotely exploited to steal sensitive information, such as user login credentials.

    You should upgrade to Apache Cordova 3.5.1 or higher as soon as possible. For more information about the vulnerabilities, and for guidance on upgrading Apache Cordova, please see http://cordova.apache.org/announcements ... d-351.html.

    Please note, applications with vulnerabilities that expose users to risk of compromise may be considered “dangerous products” and subject to removal from Google Play.

    Regards,

    Google Play Team

    ©2014 Google Inc.

    1600 Amphitheatre Parkway

    Mountain View, CA 94043

  • I got the same message. In my case I'm using Crosswalk, so I have put the question up for Intel in another topic

    If you're compiling by yourself with Phonegap instead of Crosswalk sounds like maybe you just need to recompile your apk after updating to the latest version?

  • russpuppy what you're saying is that our apache cordova is "built into" Intel XDK and they have to update it for us to be able to fix this issue?

  • Have the same issue, received today:

    { note I am building APKs using Intel XDK }

    This is a notification that your net.mrexcessive.flickmath, is built on a version of Apache Cordova that contains security vulnerabilities. This includes a high severity cross-application scripting (XAS) vulnerability. Under certain circumstances, vulnerable apps could be remotely exploited to steal sensitive information, such as user login credentials.

    You should upgrade to Apache Cordova 3.5.1 or higher as soon as possible. For more information about the vulnerabilities, and for guidance on upgrading Apache Cordova, please see http://cordova.apache.org/announcements ... d-351.html.

    Please note, applications with vulnerabilities that expose users to risk of compromise may be considered “dangerous products” and subject to removal from Google Play.

    Regards,

    Google Play Team

  • alvarop I think so ... but honestly I don't yet know enough about Crosswalk to be completely sure

  • Try Construct 3

    Develop games in your browser. Powerful, performant & highly capable.

    Try Now Construct 3 users don't see these ads
  • russpuppy alvarop anyway out of our control - which is very frustrating! I miss developing for a single platform sometimes... all the intervening opaque stuff that happens...

  • Why don't you just update your apps...

  • This is what IntelRobert said :

    Crosswalk 8 (beta build in XDK) includes apache cordova 3.5.0. Crosswalk team will need to update, test, and then we will need to update our servers. This normally takes about a week, but I haven't gotten a firm date on how long it will take. After that is done, you would just need to build again and republish.

    This problem affects most users of cordova/phonegap.

    And Tekniko, that's not how these things work.

  • Funny, that's how my apps work.

  • Tekniko it's out of our hands because the XDK needs to be updated. IntelRobert says it will happen after Crosswalk do their own update... so Cordova->Crosswalk delay, then Crosswalk->XDK delay then XDK->us doing rebuilds. Hopefully GooglePlay will hold off from removing things until after that whole chain of rebuilds is complete.

  • Maybe Tekniko knows something we don't, then. If you do, please do share how to update our apps

  • wow, ok,,........ thanks everyone.

  • Ashley

  • Not sure why you tagged me. I don't see anything for us to do on Construct 2's side, looks like you just need to rebuild your apps.

  • thought you might have some input....

    Sorry.

Jump to:
Active Users
There are 2 visitors browsing this topic (0 users and 2 guests)