CVE-2020-7653: Medium severity synk broker vulnerability
Published May 29, 2020
·Updated
All versions of snyk-broker before 4.80.0 are vulnerable to Arbitrary File Read. It allows arbitrary file reads for users with access to Snyk's internal network by creating symlinks to match whitelisted paths.
Affected Software
1 affected component
Synk Broker<4.80.0
Remediation
Patch Available
Event History
May 29, 2020
CVE Published
via MITRE·08:40 PM
Data Sourced
via MITRE·08:40 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2020-7653?
CVE-2020-7653 has a high severity level due to its potential for arbitrary file reading which could lead to sensitive information exposure.
2
How do I fix CVE-2020-7653?
To fix CVE-2020-7653, update snyk-broker to version 4.80.0 or later.
3
Who is affected by CVE-2020-7653?
Any user with access to the Snyk internal network running snyk-broker versions before 4.80.0 is affected by CVE-2020-7653.
4
What type of attack does CVE-2020-7653 enable?
CVE-2020-7653 enables attackers to perform arbitrary file reads on affected systems.
5
Is CVE-2020-7653 exploit easy to execute?
Yes, the exploit for CVE-2020-7653 is relatively straightforward, as it requires only the ability to create symlinks.