Insecure Policy Affecting expo-secure-store package, versions <9.1.0


Severity

Recommended
0.0
critical
0
10

CVSS assessment made by Snyk's Security Team

    Threat Intelligence

    EPSS
    0.22% (61st percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk ID SNYK-JS-EXPOSECURESTORE-2437082
  • published 26 Jan 2022
  • disclosed 26 Aug 2020
  • credit Unknown

How to fix?

Upgrade expo-secure-store to version 9.1.0 or higher.

Overview

expo-secure-store is a provides a way to encrypt and securely store key–value pairs locally on the device.

Affected versions of this package are vulnerable to Insecure Policy. On iOS it provides the insecure kSecAttrAccessibleAlwaysThisDeviceOnly policy when WHEN_UNLOCKED_THIS_DEVICE_ONLY is used.

CVSS Scores

version 3.1
Expand this section

Snyk

Recommended
9.8 critical
  • Attack Vector (AV)
    Network
  • Attack Complexity (AC)
    Low
  • Privileges Required (PR)
    None
  • User Interaction (UI)
    None
  • Scope (S)
    Unchanged
  • Confidentiality (C)
    High
  • Integrity (I)
    High
  • Availability (A)
    High
Expand this section

NVD

9.8 critical