CVE-2020-7650 Vulnerability Details

  /     /     /  

CVE-2020-7650 Metadata Quick Info

CVE Published: 29/05/2020 | CVE Updated: 04/08/2024 | CVE Year: 2020
Source: snyk | Vendor: n/a | Product: snyk-broker
Status : PUBLISHED

CVE-2020-7650 Description

All versions of snyk-broker after 4.72.0 including and before 4.73.1 are vulnerable to Arbitrary File Read. It allows arbitrary file reads to users with access to Snyk\'s internal network of any files ending in the following extensions: yaml, yml or json.

Metrics

CVSS Version: 3.1 | Base Score: n/a
Vector: n/a

l➤ Exploitability Metrics:
    Attack Vector (AV)*
    Attack Complexity (AC)*
    Privileges Required (PR)*
    User Interaction (UI)*
    Scope (S)*

l➤ Impact Metrics:
    Confidentiality Impact (C)*
    Integrity Impact (I)*
    Availability Impact (A)*

Weakness Enumeration (CWE)

CWE-ID:
CWE Name: Arbitrary File Read
Source: n/a

Common Attack Pattern Enumeration and Classification (CAPEC)

CAPEC-ID:
CAPEC Description:


Source: NVD (National Vulnerability Database).