CVE-2020-7650: Path Traversal
Published May 29, 2020
·Updated
All versions of snyk-broker after 4.72.0 including and before 4.73.1 are vulnerable to Arbitrary File Read. It allows arbitrary file reads to users with access to Snyk's internal network of any files ending in the following extensions: yaml, yml or json.
Affected Software
1 affected component
Synk Broker>=4.72.0<4.73.1
Remediation
Patch Available
Event History
May 29, 2020
CVE Published
via MITRE·09:11 PM
Data Sourced
via MITRE·09:11 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2020-7650?
CVE-2020-7650 is classified as a medium severity vulnerability.
2
How do I fix CVE-2020-7650?
To fix CVE-2020-7650, upgrade snyk-broker to a version greater than 4.73.1.
3
What types of files are affected by CVE-2020-7650?
CVE-2020-7650 allows arbitrary file reads of files ending in yaml, yml, or json.
4
Who is impacted by CVE-2020-7650?
Users with access to Snyk's internal network are impacted by CVE-2020-7650.
5
What versions of snyk-broker are vulnerable to CVE-2020-7650?
All versions of snyk-broker between 4.72.0 and 4.73.1 are vulnerable to CVE-2020-7650.