OSV 1.4.0 · github-reviewed · 修改于 2021-07-30 01:23
发布时间
2020-06-04 06:02
GitHub 审查时间
2020-06-02 03:42
NVD 发布时间
2020-05-30 05:15
源文件
advisories/github-reviewed/2020/06/GHSA-4vj3-f849-5r48/GHSA-4vj3-f849-5r48.json
All versions of snyk-broker before 4.80.0 are vulnerable to Arbitrary File Read. It allows arbitrary file reads for users with access to Snyk's internal network by creating symlinks to match whitelisted paths.