CVE-2020-7654: High severity synk broker vulnerability
Published May 29, 2020
·Updated
All versions of snyk-broker before 4.73.1 are vulnerable to Information Exposure. It logs private keys if logging level is set to DEBUG.
Affected Software
1 affected component
Synk Broker<4.73.1
Remediation
Patch Available
Event History
May 29, 2020
CVE Published
via MITRE·09:09 PM
Data Sourced
via MITRE·09:09 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2020-7654?
CVE-2020-7654 has a medium severity rating due to the potential information exposure of sensitive data.
2
How do I fix CVE-2020-7654?
To fix CVE-2020-7654, update snyk-broker to version 4.73.1 or later.
3
What type of information is exposed by CVE-2020-7654?
CVE-2020-7654 exposes private keys when the logging level is set to DEBUG.
4
Which versions of snyk-broker are affected by CVE-2020-7654?
All versions of snyk-broker prior to 4.73.1 are affected by CVE-2020-7654.
5
Is the information logged by snyk-broker under CVE-2020-7654 secure?
No, the information logged under CVE-2020-7654 is not secure as it includes private keys.