All versions of snyk-broker after 4.72.0 including and before 4.73.1 are vulnerable to Arbitrary File Read. It allows arbitrary file reads to users with access to Snyk's internal network of any files ending in the following extensions: yaml, yml or json.
References
Link | Resource |
---|---|
https://snyk.io/vuln/SNYK-JS-SNYKBROKER-570609 | Patch Vendor Advisory |
https://updates.snyk.io/snyk-broker-security-fixes-152338 | Vendor Advisory |
https://snyk.io/vuln/SNYK-JS-SNYKBROKER-570609 | Patch Vendor Advisory |
https://updates.snyk.io/snyk-broker-security-fixes-152338 | Vendor Advisory |
Configurations
History
21 Nov 2024, 05:37
Type | Values Removed | Values Added |
---|---|---|
References | () https://snyk.io/vuln/SNYK-JS-SNYKBROKER-570609 - Patch, Vendor Advisory | |
References | () https://updates.snyk.io/snyk-broker-security-fixes-152338 - Vendor Advisory |
Information
Published : 2020-05-29 22:15
Updated : 2024-11-21 05:37
NVD link : CVE-2020-7650
Mitre link : CVE-2020-7650
CVE.ORG link : CVE-2020-7650
JSON object : View
Products Affected
synk
- broker
CWE
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')