Hello,
I recently reached out to google play support and they sent me this message:
Hi,
Thanks for contacting Google Play Developer Support. I understand you have some questions about the Apache Cordova security vulnerability.I see that version 39 of your app is currently using the following vulnerable implementation of Apache Cordova:
assets.www.lib.phonegap.lib.android.cordova.js
assets.www.lib.phonegap.lib.android.example.assets.www.cordova.js
assets.www.lib.phonegap.lib.android.framework.assets.www.cordova.js
assets.www.lib.phonegap.lib.blackberry.bbos.example.lib.cordova.2.9.0.javascript.cordova.js
assets.www.lib.phonegap.lib.blackberry.bbos.example.www.cordova.js
assets.www.lib.phonegap.lib.ios.CordovaLib.cordova.js
assets.www.lib.phonegap.lib.windows-phone.common.www.cordova.js
assets.www.lib.phonegap.lib.windows.windows8.cordova.js
assets.www.lib.phonegap.lib.windows.windows8.template.www.cordova.js
You’ll need to upgrade your app to use Apache Cordova v.4.1.1 or higher. New apps or updates containing older versions of Apache Cordova will be blocked.
I already updated to the latest version of cordova via npm and upon resubmitting it still got rejected.