logo

CVE-2020-7653 snyk-broker

Package

Manager: npm
Name: snyk-broker
Vulnerable Version: >=0 <4.80.0

Severity

Level: Medium

CVSS v3.1: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N

EPSS: 0.00393 pctl0.59489

Details

Arbitrary File Read in Snyk Broker All versions of snyk-broker before 4.80.0 are vulnerable to Arbitrary File Read. It allows arbitrary file reads for users with access to Snyk's internal network by creating symlinks to match whitelisted paths.

Metadata

Created: 2020-06-03T22:02:21Z
Modified: 2021-07-29T17:23:47Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/06/GHSA-4vj3-f849-5r48/GHSA-4vj3-f849-5r48.json
CWE IDs: ["CWE-59"]
Alternative ID: GHSA-4vj3-f849-5r48
Finding: F076
Auto approve: 1