Junglewise Threat Intelligence

Sentry React Native SDK auth token leakage in Expo plugin

Severity: info · Published 2024-03-01

Vendors: Sentry, npm.

Executive brief

The Sentry React Native SDK allows developers to configure authentication tokens for debugging purposes. Versions 5.16.0 through 5.19.0 incorrectly embed these tokens into compiled application bundles, which could expose the tokens if the app is published. An attacker with access to a published app bundle could extract the token and use it to compromise Sentry project data and settings.

Technical details

This vulnerability is an information disclosure (CWE-200) affecting the Sentry React Native SDK's Expo plugin. The root cause is improper handling of the optional authToken configuration parameter during the application bundling process. When developers set authToken in the plugin configuration for debugging, it was embedded in the final application bundle rather than being removed or excluded. An attacker with access to the compiled app bundle (via reverse engineering or from public app stores) can extract the token. The vulnerability requires the developer to explicitly configure the authToken parameter and publish the resulting app. Patched in version 5.19.1, which now removes the authToken before bundling and issues a warning if the parameter is set.

Affected products

  • Sentry React Native SDK 5.16.0 through 5.19.0

Timeline

  • 2024-03-01: disclosed
  • 2024-03-01: patched: version 5.19.1 released with fix

References