Executive brief
Snyk Broker is a tool that securely proxies connections between Snyk's cloud service and on-premise Git repositories and Jira. A vulnerability in versions before 4.79.0 allows authenticated users with access to Snyk's internal network to read arbitrary files on the broker through the GitHub Commits API patch history endpoint. This could expose sensitive configuration files or credentials stored on systems running the broker.
Technical details
The vulnerability is a path traversal issue (CWE-22) in Snyk Broker's handling of GitHub Commits API responses. The vulnerable component fails to properly sanitize patch history data returned from GitHub, allowing an authenticated attacker with network access to Snyk's internal infrastructure to construct requests that read arbitrary files on the broker system. The attack requires authentication and internal network access, limiting exposure to trusted users or those who have breached the internal network perimeter. An attacker can achieve partial file reads of sensitive files, potentially obtaining configuration data or credentials. The vulnerability was patched in version 4.79.0.
Affected products
- Snyk snyk-broker before 4.79.0
Timeline
- 2020-05-28: disclosed
- 2020-06-03: advisory
- 2020-06-03: patched: Version 4.79.0 released