mirror of
https://github.com/0xMarcio/cve.git
synced 2026-05-31 22:31:34 +02:00
18 lines
745 B
Markdown
18 lines
745 B
Markdown
### [CVE-2020-7650](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-7650)
|
|

|
|

|
|

|
|
|
|
### Description
|
|
|
|
All versions of snyk-broker after 4.72.0 including and before 4.73.1 are vulnerable to Arbitrary File Read. It allows arbitrary file reads to users with access to Snyk's internal network of any files ending in the following extensions: yaml, yml or json.
|
|
|
|
### POC
|
|
|
|
#### Reference
|
|
- https://snyk.io/vuln/SNYK-JS-SNYKBROKER-570609
|
|
|
|
#### Github
|
|
No PoCs found on GitHub currently.
|
|
|