@sentry/react-native@5.17.0 vulnerabilities

Official Sentry SDK for react-native

Direct Vulnerabilities

Known vulnerabilities in the @sentry/react-native package. This does not include vulnerabilities belonging to this package’s dependencies.

Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for free
Vulnerability Vulnerable Version
  • L
Insufficiently Protected Credentials

@sentry/react-native is an Official Sentry SDK for react-native

Affected versions of this package are vulnerable to Insufficiently Protected Credentials in the form of the authToken configuration parameter, intended for debugging use, being exposed to attackers.

Note: After upgrading the token must be rotated if an insecure one was set via the authToken config option.

How to fix Insufficiently Protected Credentials?

Upgrade @sentry/react-native to version 5.19.1 or higher.

>=5.16.0 <5.19.1