Lucene search

K
osvGoogleOSV:GHSA-9XV2-548X-5H79
HistoryJun 03, 2020 - 10:02 p.m.

Arbitrary File Read in Snyk Broker

2020-06-0322:02:19
Google
osv.dev
10

EPSS

0.001

Percentile

48.5%

All versions of snyk-broker before 4.72.2 are vulnerable to Arbitrary File Read. It allows arbitrary file reads for users who have access to Snyk’s internal network by appending the URL with a fragment identifier and a whitelisted path e.g. #package.json

EPSS

0.001

Percentile

48.5%

Related for OSV:GHSA-9XV2-548X-5H79