CVE-2020-7648: Path Traversal
Published May 29, 2020
·Updated
All versions of snyk-broker before 4.72.2 are vulnerable to Arbitrary File Read. It allows arbitrary file reads for users who have access to Snyk's internal network by appending the URL with a fragment identifier and a whitelisted path e.g. #package.json
Affected Software
1 affected component
Synk Broker<4.72.2
Remediation
Patch Available
Event History
May 29, 2020
CVE Published
via MITRE·09:06 PM
Data Sourced
via MITRE·09:06 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2020-7648?
CVE-2020-7648 is considered a high-severity issue due to its potential for unauthorized file access.
2
How do I fix CVE-2020-7648?
To fix CVE-2020-7648, upgrade Snyk Broker to version 4.72.2 or later immediately.
3
Who is affected by CVE-2020-7648?
All users of Snyk Broker versions prior to 4.72.2 who have access to the internal network are affected.
4
What kind of vulnerability is CVE-2020-7648?
CVE-2020-7648 is an Arbitrary File Read vulnerability that allows unauthorized access to sensitive files.
5
Can CVE-2020-7648 be exploited remotely?
CVE-2020-7648 requires access to Snyk's internal network, making it not a remote exploitation issue.