logo

CVE-2020-7651 snyk-broker

Package

Manager: npm
Name: snyk-broker
Vulnerable Version: >=0 <4.79.0

Severity

Level: Medium

CVSS v3.1: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N

EPSS: 0.00233 pctl0.46005

Details

Arbitrary File Read in Snyk Broker All versions of snyk-broker before 4.79.0 are vulnerable to Arbitrary File Read. It allows partial file reads for users who have access to Snyk's internal network via patch history from GitHub Commits API.

Metadata

Created: 2020-06-03T22:02:11Z
Modified: 2021-07-29T17:23:08Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/06/GHSA-45hw-29x7-9x95/GHSA-45hw-29x7-9x95.json
CWE IDs: ["CWE-22"]
Alternative ID: GHSA-45hw-29x7-9x95
Finding: F063
Auto approve: 1