MEDIUM5.3
GHSA-6xhg-q9c8-rj32
Credential leak in react-native-fast-image
Quick fix
GHSA-6xhg-q9c8-rj32 — react-native-fast-image: upgrade to the fixed version with the command below.
npm install react-native-fast-image@8.3.0Details
This affects all versions before version 8.3.0 of package react-native-fast-image. When an image with `source={{uri: "...", headers: { host: "somehost.com", authorization: "..." }}` is loaded, all other subsequent images will use the same headers, this can lead to signing credentials or other session tokens being leaked to other servers.
Are you affected?
Enter the version of the package you're using.
Affected packages
npm/react-native-fast-image
Introduced in:
0Fixed in: 8.3.0Fix
npm install react-native-fast-image@8.3.0References
- https://nvd.nist.gov/vuln/detail/CVE-2020-7696[ADVISORY]
- https://github.com/DylanVann/react-native-fast-image/issues/690[WEB]
- https://github.com/DylanVann/react-native-fast-image/pull/691[WEB]
- https://github.com/DylanVann/react-native-fast-image/commit/4a7cd64f5b0aa40b04d63ccb105ee2b511abe624[WEB]
- https://snyk.io/vuln/SNYK-JS-REACTNATIVEFASTIMAGE-572228[WEB]