All versions of snyk-broker after 4.72.0 including and before 4.73.1 are vulnerable to Arbitrary File Read. It allows arbitrary file reads to users with access to Snyk's internal network of any files ending in the following extensions: yaml, yml or json.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2020-0448 | All versions of snyk-broker after 4.72.0 including and before 4.73.1 are vulnerable to Arbitrary File Read. It allows arbitrary file reads to users with access to Snyk's internal network of any files ending in the following extensions: yaml, yml or json. |
Github GHSA |
GHSA-2fmp-7xwf-wvwr | Arbitrary File Read in Snyk Broker |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Status: PUBLISHED
Assigner: snyk
Published:
Updated: 2024-08-04T09:33:19.992Z
Reserved: 2020-01-21T00:00:00
Link: CVE-2020-7650
No data.
Status : Modified
Published: 2020-05-29T22:15:10.693
Modified: 2024-11-21T05:37:32.570
Link: CVE-2020-7650
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA