Security Advisory

CVE-2020-7653

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2020-05-29 20:40:22
Last updated 2024-08-04 09:33:19
Assigner snyk
CVSS score not scored
State PUBLISHED

Description

All versions of snyk-broker before 4.80.0 are vulnerable to Arbitrary File Read. It allows arbitrary file reads for users with access to Snyk's internal network by creating symlinks to match whitelisted paths.