Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:25542
HistoryJun 01, 2020 - 8:51 a.m.

Arbitrary File Read

2020-06-0108:51:52
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
8

EPSS

0.001

Percentile

48.5%

snyk-broker is vulnerable to information disclosure. The vulnerability exists because it does not properly remove the information after a fragment identifier of the URL, allowing a user with access to Snyk’s internal network to read arbitrary file by appending the URL with a fragment identifier and a whitelisted path e.g. #package.json.

EPSS

0.001

Percentile

48.5%

Related for VERACODE:25542