Vulnerabilities/

Credential leak in react-native-fast-image

Severity:
Medium

Description

This affects all versions before version 8.3.0 of package react-native-fast-image. When an image with source= is loaded, all other subsequent images will use the same headers, this can lead to signing credentials or other session tokens being leaked to other servers.

Recommendation

Update the react-native-fast-image package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
react-native-fast-image
Anything's wrong? Let us know Last updated on September 12, 2023

This issue is available in SmartScanner Professional

See Pricing