First published: Mon Jul 25 2022(Updated: )
This affects the package snyk-broker before 4.73.0. It allows arbitrary file reads for users with access to Snyk's internal network via directory traversal.
Credit: report@snyk.io
Affected Software | Affected Version | How to fix |
---|---|---|
Snyk Broker | <4.73.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2020-7649 is medium.
The software affected by CVE-2020-7649 is Snyk Broker version up to and excluding 4.73.0.
CVE-2020-7649 can be exploited by users with access to Snyk's internal network using directory traversal to perform arbitrary file reads.
Yes, the fix for CVE-2020-7649 is included in Snyk Broker version 4.73.0 and later.
The Common Weakness Enumeration (CWE) ID of CVE-2020-7649 is CWE-22.