Junglewise Threat Intelligence

CVE-2020-7651: Snyk Broker arbitrary file read via patch history

CVE-2020-7651 · Severity: low · CVSS 3.1 · Published 2020-06-03

Technologies: Snyk Broker, snyk-broker (npm). Vendors: Snyk, npm.

Executive brief

Snyk Broker is a tool that securely proxies connections between Snyk's cloud service and on-premise Git repositories and Jira. A vulnerability in versions before 4.79.0 allows authenticated users with access to Snyk's internal network to read arbitrary files on the broker through the GitHub Commits API patch history endpoint. This could expose sensitive configuration files or credentials stored on systems running the broker.

Technical details

The vulnerability is a path traversal issue (CWE-22) in Snyk Broker's handling of GitHub Commits API responses. The vulnerable component fails to properly sanitize patch history data returned from GitHub, allowing an authenticated attacker with network access to Snyk's internal infrastructure to construct requests that read arbitrary files on the broker system. The attack requires authentication and internal network access, limiting exposure to trusted users or those who have breached the internal network perimeter. An attacker can achieve partial file reads of sensitive files, potentially obtaining configuration data or credentials. The vulnerability was patched in version 4.79.0.

Affected products

  • Snyk snyk-broker before 4.79.0

Timeline

  • 2020-05-28: disclosed
  • 2020-06-03: advisory
  • 2020-06-03: patched: Version 4.79.0 released

References

Related threats