Описание
All versions of snyk-broker before 4.72.2 are vulnerable to Arbitrary File Read. It allows arbitrary file reads for users who have access to Snyk's internal network by appending the URL with a fragment identifier and a whitelisted path e.g. #package.json
Ссылки
- PatchVendor Advisory
- Vendor Advisory
- PatchVendor Advisory
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 4.72.2 (исключая)
cpe:2.3:a:synk:broker:*:*:*:*:*:*:*:*
EPSS
Процентиль: 60%
0.00393
Низкий
6.5 Medium
CVSS3
4 Medium
CVSS2
Дефекты
CWE-22
Связанные уязвимости
EPSS
Процентиль: 60%
0.00393
Низкий
6.5 Medium
CVSS3
4 Medium
CVSS2
Дефекты
CWE-22