CVE-2020-7649: Directory Traversal
Published Jul 25, 2022
·Updated
This affects the package snyk-broker before 4.73.0. It allows arbitrary file reads for users with access to Snyk's internal network via directory traversal.
Affected Software
1 affected component
Snyk Broker Node.js<4.73.0
Remediation
Event History
Jul 25, 2022
CVE Published
via MITRE·02:07 PM
Data Sourced
via MITRE·02:07 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2020-7649?
The severity of CVE-2020-7649 is medium.
2
What software is affected by CVE-2020-7649?
The software affected by CVE-2020-7649 is Snyk Broker version up to and excluding 4.73.0.
3
How can CVE-2020-7649 be exploited?
CVE-2020-7649 can be exploited by users with access to Snyk's internal network using directory traversal to perform arbitrary file reads.
4
Is there a fix for CVE-2020-7649?
Yes, the fix for CVE-2020-7649 is included in Snyk Broker version 4.73.0 and later.
5
What is the Common Weakness Enumeration (CWE) ID of CVE-2020-7649?
The Common Weakness Enumeration (CWE) ID of CVE-2020-7649 is CWE-22.