A vulnerability in the expo.io framework allows an...
Critical severity
Unreviewed
Published
Apr 24, 2023
to the GitHub Advisory Database
•
Updated Apr 4, 2024
Description
Published by the National Vulnerability Database
Apr 24, 2023
Published to the GitHub Advisory Database
Apr 24, 2023
Last updated
Apr 4, 2024
A vulnerability in the expo.io framework allows an attacker to take over accounts and steal credentials on an application/website that configured the "Expo AuthSession Redirect Proxy" for social sign-in. This can be achieved once a victim clicks a malicious link. The link itself may be sent to the victim in various ways (including email, text message, an attacker-controlled website, etc).
References