Junglewise Threat Intelligence

CVE-2020-7649: snyk-broker path traversal vulnerability

CVE-2020-7649 · Severity: low · CVSS 3.1 · Published 2022-07-26

Technologies: Snyk Broker, snyk-broker (npm). Vendors: Snyk, npm.

Executive brief

snyk-broker is a tool that facilitates secure connections between Snyk's cloud service and customers' internal development environments. The vulnerability allows users with network access to the internal broker to read arbitrary files on the system via directory traversal, potentially exposing sensitive source code, configuration files, or credentials.

Technical details

This is a path traversal vulnerability (CWE-22) in snyk-broker before version 4.73.0 that allows unauthenticated or authenticated internal users to read arbitrary files via directory traversal sequences in file path requests. The vulnerability requires the attacker to have network access to the Snyk broker service (typically an internal network resource), but does not require special privileges or user interaction. An attacker can bypass intended file access restrictions and read sensitive files outside the intended directory scope. The fix was applied in version 4.73.0, which adds validation to reject paths containing directory traversal patterns.

Affected products

  • Snyk broker before 4.73.0

Timeline

  • 2022-07-26: disclosed
  • 2022-07-26: patched: Version 4.73.0 released with fix

References

Related threats