Flutter应用发布Google Play遇OpenSSL 1.1.1h漏洞警告求助
Google Play警告应用使用易受攻击的OpenSSL 1.1.1h版本的排查与解决疑问
发布应用新版本至Google Play时,收到警告:应用使用了易受攻击的OpenSSL版本(具体为1.1.1h)。
开发环境信息
[✓] Flutter (Channel stable, 3.3.7, on macOS 13.0 22A380 darwin-arm, locale en-NL) • Flutter version 3.3.7 on channel stable at /Users/_________/Documents/flutter • Upstream repository https://github.com/flutter/flutter.git • Framework revision e99c9c7cd9 (7 days ago), 2022-11-01 16:59:00 -0700 • Engine revision 857bd6b74c • Dart version 2.18.4 • DevTools version 2.15.0 [✓] Android toolchain - develop for Android devices (Android SDK version 33.0.0) • Android SDK at /Users/_________/Library/Android/sdk • Platform android-33, build-tools 33.0.0 • Java binary at: /Applications/Android Studio.app/Contents/jre/Contents/Home/bin/java • Java version OpenJDK Runtime Environment (build 11.0.13+0-b1751.21-8125866) • All Android licenses accepted. [✓] Xcode - develop for iOS and macOS (Xcode 14.1) • Xcode at /Applications/Xcode.app/Contents/Developer • Build 14B47b • CocoaPods version 1.11.3 [✓] Android Studio (version 2021.3) • Android Studio at /Applications/Android Studio.app/Contents • Flutter plugin can be installed from: 🔨 https://plugins.jetbrains.com/plugin/9212-flutter • Dart plugin can be installed from: 🔨 https://plugins.jetbrains.com/plugin/6351-dart • Java version OpenJDK Runtime Environment (build 11.0.13+0-b1751.21-8125866) [✓] VS Code (version 1.71.2) • VS Code at /Applications/Visual Studio Code.app/Contents • Flutter extension can be installed from: 🔨 https://marketplace.visualstudio.com/items?itemName=Dart-Code.flutter [✓] Connected device (2 available) • sdk gphone64 arm64 (mobile) • emulator-5554 • android-arm64 • Android 12 (API 31) (emulator) • iPhone 13 pro (mobile) • 893E06BD-1977-495E-A6E8-A388953D0C13 • ios • com.apple.CoreSimulator.SimRuntime.iOS-16-1 (simulator) [✓] HTTP Host Availability • All required HTTP hosts are available • No issues found!
自上一版本新增的依赖包
- uni_links
- informers
- open_store
- android_id
- package_info_plus
- internet_connection_checker
- analyzer
已尝试的排查与解决操作
- 执行
unzip -p app-develop-debug.apk | strings | grep "OpenSSL"脚本检查APK,发现Flutter SDK中的flutter_web_sdk和APK内的libsqlcipher.so二进制文件引用了OpenSSL - 尝试基于新版本源码编译OpenSSL,但适配Android端流程过于复杂,无法完成
- 在buildscript中添加
com.bryanherbst.openssl-checker:openssl-checker:1.0.0和org.owasp:dependency-check-gradle:7.3.0插件,希望定位具体依赖包,但Flutter运行时未触发检查流程 - 升级gradle插件至7.4,将ext.kotlin_version更新为
1.7.20,设置ndkVersion为25.1.8937393,同时更新所有Android端依赖插件至最新版本,但编译后APK仍存在OpenSSL 1.1.1h的引用
疑问
- 如何定位到具体使用OpenSSL 1.1.1h的依赖包(pubspec.yaml中有不少旧包难以直接升级)
- 下一步需要检查哪些内容,才能替换为安全版本的OpenSSL
- 该问题是否属于无法解决的深层问题?
内容的提问来源于stack exchange,提问作者M A
相关产品推荐
相关产品推荐

