React Native Sms User Consent Intent Redirection Vulnerability
Moderate severity
GitHub Reviewed
Published
Apr 7, 2024
to the GitHub Advisory Database
•
Updated Apr 8, 2024
Package
Affected versions
< 1.1.5
Patched versions
1.1.5
Description
Published by the National Vulnerability Database
Apr 7, 2024
Published to the GitHub Advisory Database
Apr 7, 2024
Reviewed
Apr 8, 2024
Last updated
Apr 8, 2024
A vulnerability, which was classified as critical, has been found in kyivstarteam react-native-sms-user-consent up to 1.1.4 on Android. Affected by this issue is the function
registerReceiver
of the fileandroid/src/main/java/ua/kyivstar/reactnativesmsuserconsent/SmsUserConsentModule.kt
. The manipulation leads to improper export of android application components. Attacking locally is a requirement. Upgrading to version 1.1.5 is able to address this issue. The name of the patch is 5423dcb0cd3e4d573b5520a71fa08aa279e4c3c7. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-259508.References