PT-2024-20960 · Unknown · React Native Document Picker

CVE-2024-25466

·

Published

2024-02-16

·

Updated

2024-08-19

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions React Native Document Picker versions prior to 9.1.1 React Native Document Picker version 8.2.2 and earlier
Description A Directory Traversal issue allows a local attacker to execute arbitrary code via a crafted script to the Android library component. This issue can be exploited by a local attacker.
Recommendations For React Native Document Picker versions prior to 9.1.1, update to version 9.1.1 to resolve the issue. For React Native Document Picker version 8.2.2 and earlier, update to version 9.1.1 to resolve the issue.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-25466
GHSA-PMGM-H3CC-M4HJ

Affected Products

React Native Document Picker