CVE-2020-7651: Path Traversal
Published May 29, 2020
·Updated
All versions of snyk-broker before 4.79.0 are vulnerable to Arbitrary File Read. It allows partial file reads for users who have access to Snyk's internal network via patch history from GitHub Commits API.
Affected Software
1 affected component
Synk Broker<4.79.0
Remediation
Patch Available
Event History
May 29, 2020
CVE Published
via MITRE·08:53 PM
Data Sourced
via MITRE·08:53 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2020-7651?
CVE-2020-7651 has a medium severity rating as it allows partial file reads for users with access to Snyk's internal network.
2
How do I fix CVE-2020-7651?
To fix CVE-2020-7651, upgrade to snyk-broker version 4.79.0 or later.
3
What versions are affected by CVE-2020-7651?
All versions of snyk-broker prior to 4.79.0 are affected by CVE-2020-7651.
4
What does CVE-2020-7651 allow attackers to do?
CVE-2020-7651 allows attackers to perform arbitrary file reads if they have access to Snyk's internal network.
5
Is CVE-2020-7651 specific to any operating system?
CVE-2020-7651 is not tied to a specific operating system but affects the snyk-broker software across any OS it is installed on.