OSV 1.4.0 · github-reviewed · 修改于 2021-07-30 01:46
发布时间
2020-06-04 06:02
GitHub 审查时间
2020-06-02 03:42
NVD 发布时间
2020-05-30 06:15
源文件
advisories/github-reviewed/2020/06/GHSA-9xv2-548x-5h79/GHSA-9xv2-548x-5h79.json
All versions of snyk-broker before 4.72.2 are vulnerable to Arbitrary File Read. It allows arbitrary file reads for users who have access to Snyk's internal network by appending the URL with a fragment identifier and a whitelisted path e.g. #package.json