Description
Directory Traversal vulnerability in React Native Document Picker before 8.2.2 and 9.x before 9.1.1 allows a local attacker to execute arbitrary code via a crafted script to the Android library component.
Recommendation
Update the react-native-document-picker package to the latest compatible version. Followings are version details:
Affected version(s): **< 8.2.2 >= 9.0.0, < 9.1.1** Patched version(s): **8.2.2 9.1.1**
References
Related Issues
- Stimulsoft Dashboard.JS directory traversal vulnerability - CVE-2024-24398
- react-native-mmkv Insertion of Sensitive Information into Log File vulnerability - CVE-2024-21668
- Directory Traversal vulnerability in serve-lite - CVE-2022-21192
- react-query-streamed-hydration Cross-site Scripting vulnerability - CVE-2024-24558
You might also like:
- Tags:
- npm
- react-native-document-picker
Anything's wrong? Let us know Last updated on August 19, 2024


