QID 981887
QID 981887: Nodejs (npm) Security Update for snyk-broker (GHSA-9xv2-548x-5h79)
All versions of snyk-broker before 4.72.2 are vulnerable to Arbitrary File Read. It allows arbitrary file reads for users who have access to Snyk's internal network by appending the URL with a fragment identifier and a whitelisted path e.g. `#package.json`
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-9xv2-548x-5h79 for updates pertaining to this vulnerability.
Vendor References
- GHSA-9xv2-548x-5h79 -
github.com/advisories/GHSA-9xv2-548x-5h79
CVEs related to QID 981887
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-9xv2-548x-5h79 | snyk-broker |
|