0.2.4
4 years ago
1 years ago
Known vulnerabilities in the @react-native-aria/switch package. This does not include vulnerabilities belonging to this package’s dependencies.
Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for freeVulnerability | Vulnerable Version |
---|---|
@react-native-aria/switch is a mono repo setup with bob Affected versions of this package are vulnerable to Embedded Malicious Code that conceals a remote access trojan (RAT). A malicious actor compromised a public access token associated with one of Gluestack-UI’s contributors; This allowed the attacker to publish tampered versions of react-native-aria packages along with a @gluestack-ui/utils package to npm. How to fix Embedded Malicious Code? Avoid using all malicious instances of the | =0.2.5 |