CVE-2020-7653 – snyk-broker
Package
Manager: npm
Name: snyk-broker
Vulnerable Version: >=0 <4.80.0
Severity
Level: Medium
CVSS v3.1: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
EPSS: 0.00393 pctl0.59489
Details
Arbitrary File Read in Snyk Broker All versions of snyk-broker before 4.80.0 are vulnerable to Arbitrary File Read. It allows arbitrary file reads for users with access to Snyk's internal network by creating symlinks to match whitelisted paths.
Metadata
Created: 2020-06-03T22:02:21Z
Modified: 2021-07-29T17:23:47Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/06/GHSA-4vj3-f849-5r48/GHSA-4vj3-f849-5r48.json
CWE IDs: ["CWE-59"]
Alternative ID: GHSA-4vj3-f849-5r48
Finding: F076
Auto approve: 1