GHSA-68c2-4mpx-qh95

    Dashboard / Vulnerabilities / GHSA-68c2-4mpx-qh95

    GHSA-68c2-4mpx-qh95

    Published: 1 Mar 2024Last Modified: 1 Mar 2024

    Summary: Potential leakage of Sentry auth tokens by React Native SDK with Expo plugin

    Details: ### Impact SDK versions between and including 5.16.0 and 5.19.0 allowed Sentry auth tokens to be set in the optional authToken configuration parameter, for debugging purposes. Doing so would result in the auth token being built into the application bundle, and therefore the auth token could be potentially exposed in case the application bundle is subsequently published. You may ignore this notification if you are not using `authToken` configuration parameter in your React Native SDK configuration or did not publish apps using this way of configuring the `authToken`. If you had set the `authToken` in the plugin config previously, and built and published an app with that config, you should [rotate your token](https://docs.sentry.io/product/accounts/auth-tokens/). ### Patches The behavior that allowed setting an `authToken` parameter was fixed in SDK version 5.19.1 where, if this parameter was set, you will see a warning and the `authToken` would be removed before bundling the application. ### Workarounds 1. Remove `authToken` from the plugin configuration. 2. If you had set the `authToken` in the plugin config previously, and built and published an app with that config, you should [rotate your token](https://docs.sentry.io/product/accounts/auth-tokens/). ### References * [sentry-react-native 5.19.1 release notes](https://github.com/getsentry/sentry-react-native/releases/tag/5.19.1) * https://github.com/getsentry/sentry-docs/pull/9244

    Affected packages

    Package

    Name: @sentry/react-native

    Purl: pkg:npm/%40sentry/react-native

    Affected ranges

    Type: SEMVER

    Events:

    Introduced- 5.16.0
    Fixed -5.19.1

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-68c2-4mpx-qh95 | CVE-DB