QID 982582
QID 982582: Nodejs (npm) Security Update for react-native-fast-image (GHSA-6xhg-q9c8-rj32)
This affects all versions before version 8.3.0 of package react-native-fast-image. When an image with source={{uri: "...", headers: { host: "somehost.com", authorization: "..." }} is loaded, all other subsequent images will use the same headers, this can lead to signing credentials or other session tokens being leaked to other servers.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-6xhg-q9c8-rj32 for updates pertaining to this vulnerability.
Vendor References
- GHSA-6xhg-q9c8-rj32 -
github.com/advisories/GHSA-6xhg-q9c8-rj32
CVEs related to QID 982582
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-6xhg-q9c8-rj32 | react-native-fast-image |
|