All versions of snyk-broker after 4.72.0 including and before 4.73.1 are vulnerable to Arbitrary File Read. It allows arbitrary file reads to users with access to Snyk's internal network of any files ending in the following extensions: yaml, yml or json.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: snyk

Published: 2020-05-29T21:11:39

Updated: 2024-08-04T09:33:19.992Z

Reserved: 2020-01-21T00:00:00

Link: CVE-2020-7650

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2020-05-29T22:15:10.693

Modified: 2024-11-21T05:37:32.570

Link: CVE-2020-7650

cve-icon Redhat

No data.