CVE-2020-7649
MEDIUMSnyk Broker < 4.73.0 - Path Traversal via Directory Traversal
Title source: llmDescription
This affects the package snyk-broker before 4.73.0. It allows arbitrary file reads for users with access to Snyk's internal network via directory traversal.
References (3)
Core 3
Core References
Exploit, Vendor Advisory x_refsource_misc
https://security.snyk.io/vuln/SNYK-JS-SNYKBROKER-570608
Patch, Third Party Advisory x_refsource_misc
https://github.com/snyk/broker/commit/90e0bac07a800b7c4c6646097c9c89d6b878b429
Vendor Advisory x_refsource_misc
https://updates.snyk.io/snyk-broker-security-fixes-152338
Scores
CVSS v3
4.9
EPSS
0.0137
EPSS Percentile
68.4%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Details
CWE
CWE-22
Status
published
Products (2)
npm/snyk-broker
0 - 4.73.0npm
snyk/broker
< 4.73.0
Published
Jul 25, 2022
Tracked Since
Feb 18, 2026