VDB
Sign up
MEDIUM6.5

GHSA-2fmp-7xwf-wvwr

Arbitrary File Read in Snyk Broker

Quick fix

GHSA-2fmp-7xwf-wvwr — snyk-broker: upgrade to the fixed version with the command below.

npm install snyk-broker@4.73.1

Details

All versions of snyk-broker after 4.72.0 including and before 4.73.1 are vulnerable to Arbitrary File Read. It allows arbitrary file reads to users with access to Snyk's internal network of any files ending in the following extensions: yaml, yml or json.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/snyk-broker
Introduced in: 0Fixed in: 4.73.1
Fixnpm install snyk-broker@4.73.1

References