Insecure Policy Affecting expo-secure-store package, versions <9.1.0
Threat Intelligence
EPSS
0.22% (61st
percentile)
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-JS-EXPOSECURESTORE-2437082
- published 26 Jan 2022
- disclosed 26 Aug 2020
- credit Unknown
Introduced: 26 Aug 2020
CVE-2020-24653 Open this link in a new tabHow to fix?
Upgrade expo-secure-store
to version 9.1.0 or higher.
Overview
expo-secure-store is a provides a way to encrypt and securely store key–value pairs locally on the device.
Affected versions of this package are vulnerable to Insecure Policy. On iOS it provides the insecure kSecAttrAccessibleAlwaysThisDeviceOnly
policy when WHEN_UNLOCKED_THIS_DEVICE_ONLY
is used.
References
CVSS Scores
version 3.1