CVE-2025-45001

react-native-keys 0.7.11 is vulnerable to sensitive information disclosure (remote) as encryption cipher and Base64 chunks are stored as plaintext in the compiled native binary. Attackers can extract these secrets using basic static analysis tools.
Configurations

No configuration.

History

12 Jun 2025, 16:06

Type Values Removed Values Added
Summary
  • (es) React-native-keys 0.7.11 es vulnerable a la divulgación de información confidencial (remota), ya que el cifrado y los fragmentos Base64 se almacenan como texto plano en el binario nativo compilado. Los atacantes pueden extraer estos secretos mediante herramientas básicas de análisis estático.

09 Jun 2025, 20:15

Type Values Removed Values Added
References () https://gist.github.com/ch3tanbug/44aedff79dd5d2d6beadbffcd01e0de5 - () https://gist.github.com/ch3tanbug/44aedff79dd5d2d6beadbffcd01e0de5 -
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5
CWE CWE-312

09 Jun 2025, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-06-09 17:15

Updated : 2025-06-12 16:06


NVD link : CVE-2025-45001

Mitre link : CVE-2025-45001

CVE.ORG link : CVE-2025-45001


JSON object : View

Products Affected

No product.

CWE
CWE-312

Cleartext Storage of Sensitive Information