CVE-2020-24653
EPSS 0.43%Expo on iOS is insecure due incorrect security attribute application
Published: 5/24/2022Modified: 11/8/2023
Description
secure-store in Expo through 9.1.0 on iOS provides the insecure kSecAttrAccessibleAlwaysThisDeviceOnly policy when WHEN_UNLOCKED_THIS_DEVICE_ONLY is used.
Affected packages (1)
- npm/expofrom 0, < 9.1.0
References (5)
- ADVISORYhttps://nvd.nist.gov/vuln/detail/CVE-2020-24653
- PATCHhttps://github.com/expo/expo
- WEBhttps://github.com/expo/expo/blob/main/packages/expo-secure-store/CHANGELOG.md
- WEBhttps://github.com/expo/expo/commit/1d82bf07fae2c96273e9189997e521359cffc1a9#diff-5b2820f378da980bd8a8185e2e1b2f9ce085d834534483f29c67932f282cc5c9
- WEBhttps://github.com/expo/expo/pull/9264