Relative Path Traversal Affecting expo-clipboard package, versions <5.0.0


Severity

Recommended
0.0
medium
0
10

CVSS assessment made by Snyk's Security Team

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk ID SNYK-JS-EXPOCLIPBOARD-6084026
  • published 30 Sep 2024
  • disclosed 23 Nov 2023
  • credit Wojciech Dróżdż

Introduced: 23 Nov 2023

CVE NOT AVAILABLE CWE-23 Open this link in a new tab

How to fix?

Upgrade expo-clipboard to version 5.0.0 or higher.

Overview

expo-clipboard is an ExpoClipboard standalone module

Affected versions of this package are vulnerable to Relative Path Traversal due to improper access control, which made it possible to read from a wrong root directory.

Note: It is not possible to get outside of the cache directory with this method, so this can only be used for files in the cache directory of the app which are also located in a directory whose name is prefixed with .clipboard - .

CVSS Scores

version 3.1
Expand this section

Snyk

Recommended
5.3 medium
  • Attack Vector (AV)
    Network
  • Attack Complexity (AC)
    Low
  • Privileges Required (PR)
    None
  • User Interaction (UI)
    None
  • Scope (S)
    Unchanged
  • Confidentiality (C)
    Low
  • Integrity (I)
    None
  • Availability (A)
    None