CVE-2020-7651 – snyk-broker
Package
Manager: npm
Name: snyk-broker
Vulnerable Version: >=0 <4.79.0
Severity
Level: Medium
CVSS v3.1: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
EPSS: 0.00233 pctl0.46005
Details
Arbitrary File Read in Snyk Broker All versions of snyk-broker before 4.79.0 are vulnerable to Arbitrary File Read. It allows partial file reads for users who have access to Snyk's internal network via patch history from GitHub Commits API.
Metadata
Created: 2020-06-03T22:02:11Z
Modified: 2021-07-29T17:23:08Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/06/GHSA-45hw-29x7-9x95/GHSA-45hw-29x7-9x95.json
CWE IDs: ["CWE-22"]
Alternative ID: GHSA-45hw-29x7-9x95
Finding: F063
Auto approve: 1