Arbitrary File Read in Snyk Broker
Moderate severity
GitHub Reviewed
Published
Jun 3, 2020
to the GitHub Advisory Database
•
Updated Jan 9, 2023
Description
Reviewed
Jun 1, 2020
Published to the GitHub Advisory Database
Jun 3, 2020
Last updated
Jan 9, 2023
All versions of snyk-broker before 4.80.0 are vulnerable to Arbitrary File Read. It allows arbitrary file reads for users with access to Snyk's internal network via directory traversal.
References