Insecure Policy Affecting expo-secure-store package, versions <9.1.0


Severity

Recommended
0.0
critical
0
10

CVSS assessment made by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.2% (58th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-JS-EXPOSECURESTORE-2437082
  • published26 Jan 2022
  • disclosed26 Aug 2020
  • creditUnknown

Introduced: 26 Aug 2020

CVE-2020-24653  (opens in a new tab)
CWE-275  (opens in a new tab)

How to fix?

Upgrade expo-secure-store to version 9.1.0 or higher.

Overview

expo-secure-store is a provides a way to encrypt and securely store key–value pairs locally on the device.

Affected versions of this package are vulnerable to Insecure Policy. On iOS it provides the insecure kSecAttrAccessibleAlwaysThisDeviceOnly policy when WHEN_UNLOCKED_THIS_DEVICE_ONLY is used.

CVSS Scores

version 3.1