All versions of snyk-broker after 4.72.0 including and before 4.73.1 are vulnerable to Arbitrary File Read. It allows arbitrary file reads to users with access to Snyk's internal network of any files ending in the following extensions: yaml, yml or json.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: snyk

Published: 2020-05-29T21:11:39

Updated: 2020-05-29T21:11:39

Reserved: 2020-01-21T00:00:00


Link: CVE-2020-7650

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2020-05-29T22:15:10.693

Modified: 2021-07-21T11:39:23.747


Link: CVE-2020-7650

JSON object: View

cve-icon Redhat Information

No data.

CWE