QID 981888
QID 981888: Nodejs (npm) Security Update for snyk-broker (GHSA-4vj3-f849-5r48)
All versions of snyk-broker before 4.80.0 are vulnerable to Arbitrary File Read. It allows arbitrary file reads for users with access to Snyk's internal network by creating symlinks to match whitelisted paths.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-4vj3-f849-5r48 for updates pertaining to this vulnerability.
Vendor References
- GHSA-4vj3-f849-5r48 -
github.com/advisories/GHSA-4vj3-f849-5r48
CVEs related to QID 981888
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-4vj3-f849-5r48 | snyk-broker |
|