在 achorein expo-share-intent 8.0.0 及更早版本中发现了一个安全漏洞。该漏洞影响 Android 文件复制例程(Android File Copy Routine)组件中的 ExpoShareIntentModule.kt 文件的 getDataColumn 函数。通过对参数 _display_name 的操作可导致路径遍历(path traversal)。此攻击需要本地访问权限。升级至 8.0.1 版本可缓解此问题。相关补丁标识为 c6900b1ed06fcc3ca4b096513
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| achorein | expo-share-intent | 8.0 |
cpe:2.3:a:achorein:expo-share-intent:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet