Insufficiently Protected Credentials Affecting @sentry/react-native package, versions >=5.16.0 <5.19.1
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-JS-SENTRYREACTNATIVE-6358886
- published 3 Mar 2024
- disclosed 1 Mar 2024
- credit Unknown
How to fix?
Upgrade @sentry/react-native
to version 5.19.1 or higher.
Overview
@sentry/react-native is an Official Sentry SDK for react-native
Affected versions of this package are vulnerable to Insufficiently Protected Credentials in the form of the authToken
configuration parameter, intended for debugging use, being exposed to attackers.
Note: After upgrading the token must be rotated if an insecure one was set via the authToken
config option.
References
CVSS Scores
version 3.1