QID 981889
QID 981889: Nodejs (npm) Security Update for snyk-broker (GHSA-45hw-29x7-9x95)
All versions of snyk-broker before 4.79.0 are vulnerable to Arbitrary File Read. It allows partial file reads for users who have access to Snyk's internal network via patch history from GitHub Commits API.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-45hw-29x7-9x95 for updates pertaining to this vulnerability.
Vendor References
- GHSA-45hw-29x7-9x95 -
github.com/advisories/GHSA-45hw-29x7-9x95
CVEs related to QID 981889
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-45hw-29x7-9x95 | snyk-broker |
|