CVE-2020-7649

Severity CVSS v4.0:
Pending analysis
Type:
CWE-22 Path Traversal
Publication date:
25/07/2022
Last modified:
01/08/2022

Description

This affects the package snyk-broker before 4.73.0. It allows arbitrary file reads for users with access to Snyk's internal network via directory traversal.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:snyk:broker:*:*:*:*:*:node.js:*:* 4.73.0 (excluding)