Hi Android Security Team,

We have also received this Cordova security alert. We would like to know 
what is the grace period before you will start pulling apps from the 
PlayStore? Based on our investigation our apps are not utilizing the 
vulnerable parts of Cordova. We are in active development for new releases 
of our apps that will remove the Cordova dependencies but these will not be 
available in the next couple of days and we need to know how long we have 
to fix the issue before Google will forcibly remove our app?

Thanks,
David


On Wednesday, October 1, 2014 10:24:54 PM UTC+1, Campbell Moss wrote:
>
> The company I work for develops apps based on Apache Cordova. We recently 
> started receiving the following email:
>
> *From:* Google Play Developer Support [
> mailto:[email protected] <javascript:>] 
> *Sent:* Wednesday, October 01, 2014 11:49 AM
> *To:* 
> *Subject:* Security Alert: Apache Cordova vulnerabilities in your Google 
> Play app
>
> *Sent:* Wednesday, October 01, 2014 11:49 AM
>
> *To:* 
>
> *Subject:* Security Alert: Apache Cordova vulnerabilities in your Google 
> Play app
>
> This is a notification that your com.x.tablet, is built on a version of 
> Apache Cordova that contains security vulnerabilities. This includes a high 
> severity cross-application scripting (XAS) vulnerability. Under certain 
> circumstances, vulnerable apps could be remotely exploited to steal 
> sensitive information, such as user login credentials.
>
> *You should upgrade to Apache Cordova 3.5.1 or higher as soon as possible.* 
> For more information about the vulnerabilities, and for guidance on 
> upgrading Apache Cordova, please see 
> http://cordova.apache.org/announcements/2014/08/04/android-351.html 
> <http://www.google.com/appserve/mkt/p/KmKdvQON6CTeZllUj7WYD83Vn9mvaw8PPuE7s-iye9mMdMg4vanAFar-c-4del1W5NMHLsvG9v08xwXupuZE5UFefpQMCEV-U7lC2BbIRTZlfP5k>
> .
>
> *Please note, applications with vulnerabilities that expose users to risk 
> of compromise may be considered “dangerous products” and subject to removal 
> from Google Play.*
>
> Regards,
>
> Google Play Team
>
>
> We were aware of this vulnerability, and during our investigation have 
> determined that our apps are not vulnerable as they don't use the intent 
> filter that permits the exploit.
>
> My question is, will Google be removing all apps that use older versions 
> of Cordova from Google Play?
>

-- 
You received this message because you are subscribed to the Google Groups 
"Android Security Discussions" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to [email protected].
To post to this group, send email to [email protected].
Visit this group at http://groups.google.com/group/android-security-discuss.
For more options, visit https://groups.google.com/d/optout.

Reply via email to