- Marquer comme nouveau
- Marquer
- S'abonner
- Sourdine
- S'abonner au fil RSS
- Surligner
- Imprimer
- Signaler un contenu inapproprié
Hello,
Today i entered on my google play dev acc and i saw that i have an error , (i made a simple game using intel XDK and upload it on google play)
Before I show you the error plz consider that I'm an amateur
So the Problem is like this:
Security alert
The application sends a static version of OpenSSL multiple security vulnerabilities. We recommend that you upgrade OpenSSL soon.
The vulnerabilities are fixed since version OpenSSL 1.0.1h, 1.0.0m and 0.9.8za. To check which version you use OpenSSL, you can run the grep tool ("$ unzip -p YourApp.apk | strings | grep" OpenSSL ""). For more information about the vulnerability, see http://www.openssl.org/news/secadv_20140605.txt.
To ensure that you have made the correct upgrade, upload updated version Developer Console and return over five hours.
Note that although it is not clear if your application is affected by these problems, applications vulnerabilities that expose users to compromise security risk can be considered 'dangerous' and can be removed from Google Play.
Ok , now how could i upgrade OpenSSL using intel xdk or how else?
Thank You
- Balises:
- Android* OS
Lien copié
- Marquer comme nouveau
- Marquer
- S'abonner
- Sourdine
- S'abonner au fil RSS
- Surligner
- Imprimer
- Signaler un contenu inapproprié
I also got a similar problem
Security alert This app is built on a version of Apache Cordova that contains security vulnerabilities. This includes a high severity cross-application scripting (XAS) vulnerability. Under certain circumstances, vulnerable apps could be remotely exploited to steal sensitive information, such as user login credentials. For more information about the vulnerabilities, and for guidance on upgrading Apache Cordova, please see http://cordova.apache.org/announcements/2014/08/04/android-351.html I think we will have to wait for an upgrade from xdk.
- Marquer comme nouveau
- Marquer
- S'abonner
- Sourdine
- S'abonner au fil RSS
- Surligner
- Imprimer
- Signaler un contenu inapproprié
Hi,
Thanks for the report. I will ask the XDK team to look into this issue.
Thanks,
Alex
- Marquer comme nouveau
- Marquer
- S'abonner
- Sourdine
- S'abonner au fil RSS
- Surligner
- Imprimer
- Signaler un contenu inapproprié
I had the same problem , in the project bar pu there 3.5.1 Cordova version
BTW anyone had my problem?
- Marquer comme nouveau
- Marquer
- S'abonner
- Sourdine
- S'abonner au fil RSS
- Surligner
- Imprimer
- Signaler un contenu inapproprié
I received a mail from Google Play with the same issue 2 days ago. Someone help to fix this please.
- Marquer comme nouveau
- Marquer
- S'abonner
- Sourdine
- S'abonner au fil RSS
- Surligner
- Imprimer
- Signaler un contenu inapproprié
Hi,
we are still discussing this internally. I will keep you updated.
Thanks,
Alex
- Marquer comme nouveau
- Marquer
- S'abonner
- Sourdine
- S'abonner au fil RSS
- Surligner
- Imprimer
- Signaler un contenu inapproprié
Ok,
I'm waiting
Btw Thank you for helping us.
- Marquer comme nouveau
- Marquer
- S'abonner
- Sourdine
- S'abonner au fil RSS
- Surligner
- Imprimer
- Signaler un contenu inapproprié
I have the same problem, I received the same message in all my apps :(
- Marquer comme nouveau
- Marquer
- S'abonner
- Sourdine
- S'abonner au fil RSS
- Surligner
- Imprimer
- Signaler un contenu inapproprié
Hi everyone I had the warning message with my games @googleplay for a week which were on and off changing everyday. And yesterday I got the same exact email from Google.
I really wish there will be an update with Intel XDK since there is a threat of our games/apps being removed from Googleplay.
- Marquer comme nouveau
- Marquer
- S'abonner
- Sourdine
- S'abonner au fil RSS
- Surligner
- Imprimer
- Signaler un contenu inapproprié
Hi,
I have a response from the XDK team:
This warning from Google Play pertains to the App Security API plugin which includes the older OpenSSL library. This plugin is being updated and will be available in the next Intel XDK release after the first of the year. In the meantime, you shouldn’t need to worry about the security as the plugin does not actually use the vulnerable part of the Open SSL code. So, you should be prepared to update your app when we get the plugin updated.
Thanks,
Alex
- Marquer comme nouveau
- Marquer
- S'abonner
- Sourdine
- S'abonner au fil RSS
- Surligner
- Imprimer
- Signaler un contenu inapproprié
Hi @Alexander Weggerle,
I just would like to ask if there is a way to publish a quick update of XDK only for this SSL problem since we see many people facing this issue. I know I am asking too much but it seems there is a danger I see that Googleplay might remove our games from the system and people are worried.
Please check the forum and the chat session in the following link in Scirra Forum:
https://www.scirra.com/forum/google-play-alert-about-openssl_t121003?start=20
It says
Murphy 2:37 PM
Currently, there's no deadline at the moment, our policy team has just states "ASAP".
Thank You and Regards
Volkan
- Marquer comme nouveau
- Marquer
- S'abonner
- Sourdine
- S'abonner au fil RSS
- Surligner
- Imprimer
- Signaler un contenu inapproprié
Hi Volkan,
thanks for your input. This is really helpful and I take that for further internal discussions.
Thanks,
Alex
- Marquer comme nouveau
- Marquer
- S'abonner
- Sourdine
- S'abonner au fil RSS
- Surligner
- Imprimer
- Signaler un contenu inapproprié
This is not the same issue as the first user posted. You simply need to rebuild your app, specifying Cordova 3.5.1 in the Project Settings of the XDK. Once you do this, you can resubmit your app to the Play Store and you should not see this message.
Ramith Hettiarachchi wrote:
I also got a similar problem
Security alert This app is built on a version of Apache Cordova that contains security vulnerabilities. This includes a high severity cross-application scripting (XAS) vulnerability. Under certain circumstances, vulnerable apps could be remotely exploited to steal sensitive information, such as user login credentials. For more information about the vulnerabilities, and for guidance on upgrading Apache Cordova, please see http://cordova.apache.org/announcements/2014/08/04/android-351.html I think we will have to wait for an upgrade from xdk.
- Marquer comme nouveau
- Marquer
- S'abonner
- Sourdine
- S'abonner au fil RSS
- Surligner
- Imprimer
- Signaler un contenu inapproprié
@Alexander Weggerle (Intel) Thank You for your concern and quick reply I really hope the issue can be resolved As soon as possible.
Also a user @Scirra forums said:
If you update the OpenSSL this fixes the problem. The errors have gone away for me after I then re built my apps
I updated here: http://cygwin.com/install.html but you can install without cygwin: http://slproweb.com/products/Win32OpenSSL.html
Just for your information.
I am glad I could be helpful.
- Marquer comme nouveau
- Marquer
- S'abonner
- Sourdine
- S'abonner au fil RSS
- Surligner
- Imprimer
- Signaler un contenu inapproprié
So , i understand that the problem will disappear after the new Intel XDK update?
Am i right?
And if yes , does antone know when will be this?
Thank's a lot.
- Marquer comme nouveau
- Marquer
- S'abonner
- Sourdine
- S'abonner au fil RSS
- Surligner
- Imprimer
- Signaler un contenu inapproprié
Hi,
We are still investigating on this and will work on an update as soon as the investigation is finished. At the moment it looks like the particular OpenSSL implementation had the security fixes backported... This is good because it means the apps are not vulnerable but on on the other side it will not help with the Google Play store.
So stay tuned we will fix it soon!
Alex
- Marquer comme nouveau
- Marquer
- S'abonner
- Sourdine
- S'abonner au fil RSS
- Surligner
- Imprimer
- Signaler un contenu inapproprié
Ok,
Thank you.
- Marquer comme nouveau
- Marquer
- S'abonner
- Sourdine
- S'abonner au fil RSS
- Surligner
- Imprimer
- Signaler un contenu inapproprié
Thanks!
JOHN H. (Intel) wrote:
This is not the same issue as the first user posted. You simply need to rebuild your app, specifying Cordova 3.5.1 in the Project Settings of the XDK. Once you do this, you can resubmit your app to the Play Store and you should not see this message.
Quote:
Ramith Hettiarachchi wrote:
I also got a similar problem
Security alert This app is built on a version of Apache Cordova that contains security vulnerabilities. This includes a high severity cross-application scripting (XAS) vulnerability. Under certain circumstances, vulnerable apps could be remotely exploited to steal sensitive information, such as user login credentials. For more information about the vulnerabilities, and for guidance on upgrading Apache Cordova, please see http://cordova.apache.org/announcements/2014/08/04/android-351.html I think we will have to wait for an upgrade from xdk.
- Marquer comme nouveau
- Marquer
- S'abonner
- Sourdine
- S'abonner au fil RSS
- Surligner
- Imprimer
- Signaler un contenu inapproprié
Hello,
Anything new about the topic?
Does anyone knows when the update will come?
- Marquer comme nouveau
- Marquer
- S'abonner
- Sourdine
- S'abonner au fil RSS
- Surligner
- Imprimer
- Signaler un contenu inapproprié
Hi,
sorry for the late update from my side. The official communication for this issue moved to this forum. You find your answers there and this forum is monitored by the XDK developers so you have a more direct contact.
Thanks,
Alex
- Marquer comme nouveau
- Marquer
- S'abonner
- Sourdine
- S'abonner au fil RSS
- Surligner
- Imprimer
- Signaler un contenu inapproprié
Hello,
I've update my app and that alert came again, solutions?

- S'abonner au fil RSS
- Marquer le sujet comme nouveau
- Marquer le sujet comme lu
- Placer ce Sujet en tête de liste pour l'utilisateur actuel
- Marquer
- S'abonner
- Page imprimable