Executive brief
Snyk Broker is a proxy service used to securely connect Snyk's scanning tools to private code repositories and internal systems like Jira. A security flaw in certain versions allows users with access to the internal network to read sensitive configuration or data files ending in .yaml, .yml, or .json. This could lead to the exposure of credentials, system configurations, or other sensitive business information stored in those file formats.
Technical details
Snyk Broker versions from 4.72.0 up to (but excluding) 4.73.1 are vulnerable to an arbitrary file read (path traversal) vulnerability, identified as CWE-22. The flaw allows an attacker with network access and low-level privileges to retrieve files from the host system, provided the files have .yaml, .yml, or .json extensions. This is particularly critical as these extensions are commonly used for configuration files containing secrets or environment variables. The vulnerability was addressed in version 4.73.1.
Affected products
- Snyk snyk-broker >=4.72.0 <4.73.1
Timeline
- 2020-05-28: disclosed: Vulnerability disclosed by Wing Chan of The Hut Group.
- 2020-05-29: advisory: NVD and Snyk published advisory details.
- 2020-06-03: advisory: GitHub Advisory published.