All versions of snyk-broker after 4.72.0 including and before 4.73.1 are vulnerable to Arbitrary File Read. It allows arbitrary file reads to users with access to Snyk's internal network of any files ending in the following extensions: yaml, yml or json.
                
            References
                    | Link | Resource | 
|---|---|
| https://snyk.io/vuln/SNYK-JS-SNYKBROKER-570609 | Patch Vendor Advisory | 
| https://updates.snyk.io/snyk-broker-security-fixes-152338 | Vendor Advisory | 
| https://snyk.io/vuln/SNYK-JS-SNYKBROKER-570609 | Patch Vendor Advisory | 
| https://updates.snyk.io/snyk-broker-security-fixes-152338 | Vendor Advisory | 
Configurations
                    History
                    21 Nov 2024, 05:37
| Type | Values Removed | Values Added | 
|---|---|---|
| References | () https://snyk.io/vuln/SNYK-JS-SNYKBROKER-570609 - Patch, Vendor Advisory | |
| References | () https://updates.snyk.io/snyk-broker-security-fixes-152338 - Vendor Advisory | 
Information
                Published : 2020-05-29 22:15
Updated : 2024-11-21 05:37
NVD link : CVE-2020-7650
Mitre link : CVE-2020-7650
CVE.ORG link : CVE-2020-7650
JSON object : View
Products Affected
                synk
- broker
CWE
                
                    
                        
                        CWE-22
                        
            Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
