All versions of snyk-broker before 4.79.0 are vulnerable to Arbitrary File Read. It allows partial file reads for users who have access to Snyk's internal network via patch history from GitHub Commits API.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: snyk

Published: 2020-05-29T20:53:29

Updated: 2020-05-29T20:53:29

Reserved: 2020-01-21T00:00:00


Link: CVE-2020-7651

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2020-05-29T21:15:10.083

Modified: 2021-07-21T11:39:23.747


Link: CVE-2020-7651

JSON object: View

cve-icon Redhat Information

No data.

CWE