CVE-2020-7652: Path Traversal
Published May 29, 2020
·Updated
All versions of snyk-broker before 4.80.0 are vulnerable to Arbitrary File Read. It allows arbitrary file reads for users with access to Snyk's internal network via directory traversal.
Affected Software
1 affected component
Synk Broker<4.80.0
Remediation
Patch Available
Event History
May 29, 2020
CVE Published
via MITRE·08:46 PM
Data Sourced
via MITRE·08:46 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2020-7652?
CVE-2020-7652 has a critical severity rating due to the potential for arbitrary file read access.
2
How do I fix CVE-2020-7652?
To fix CVE-2020-7652, upgrade snyk-broker to version 4.80.0 or later.
3
Who is affected by CVE-2020-7652?
CVE-2020-7652 affects all versions of snyk-broker prior to 4.80.0.
4
What type of attack does CVE-2020-7652 enable?
CVE-2020-7652 enables an attacker to perform arbitrary file reads through directory traversal.
5
How can I mitigate the risks of CVE-2020-7652?
To mitigate risks from CVE-2020-7652, restrict access to Snyk's internal network and upgrade to the latest version.