Relative Path Traversal Affecting expo-clipboard package, versions <5.0.0
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-JS-EXPOCLIPBOARD-6084026
- published 30 Sep 2024
- disclosed 23 Nov 2023
- credit Wojciech Dróżdż
How to fix?
Upgrade expo-clipboard
to version 5.0.0 or higher.
Overview
expo-clipboard is an ExpoClipboard standalone module
Affected versions of this package are vulnerable to Relative Path Traversal due to improper access control, which made it possible to read from a wrong root directory.
Note:
It is not possible to get outside of the cache directory with this method, so this can only be used for files in the cache directory of the app which are also located in a directory whose name is prefixed with .clipboard -
.
References
CVSS Scores
version 3.1