Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-6xhg-q9c8-rj32

Опубликовано: 18 мая 2021
Источник: github
Github: Прошло ревью
CVSS3: 5.3

Описание

Credential leak in react-native-fast-image

This affects all versions before version 8.3.0 of package react-native-fast-image. When an image with source={{uri: "...", headers: { host: "somehost.com", authorization: "..." }} is loaded, all other subsequent images will use the same headers, this can lead to signing credentials or other session tokens being leaked to other servers.

Пакеты

Наименование

react-native-fast-image

npm
Затронутые версииВерсия исправления

< 8.3.0

8.3.0

EPSS

Процентиль: 63%
0.00455
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-200

Связанные уязвимости

CVSS3: 5.3
nvd
больше 5 лет назад

This affects all versions of package react-native-fast-image. When an image with source={{uri: "...", headers: { host: "somehost.com", authorization: "..." }} is loaded, all other subsequent images will use the same headers, this can lead to signing credentials or other session tokens being leaked to other servers.

EPSS

Процентиль: 63%
0.00455
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-200