Executive brief
Snyk Broker is a service that securely relays communications between Snyk's cloud platform and private customer environments. An attacker with network access to the broker can read arbitrary files from the server through directory traversal, potentially exposing sensitive configuration files, credentials, or proprietary code stored alongside the broker.
Technical details
Snyk Broker versions before 4.80.0 contain a directory traversal vulnerability (CWE-22) in file-reading functionality. The vulnerability allows authenticated or network-adjacent attackers to bypass path restrictions and read arbitrary files on the system hosting the broker. Attack vector is network-based, requiring only low privilege access to the internal network where the broker operates. An attacker can retrieve sensitive files including credentials, keys, or application data. The vulnerability is fixed in version 4.80.0 and later.
Affected products
- Snyk Broker before 4.80.0
Timeline
- 2020-06-03: disclosed
- 2020-06-03: patched: Fix available in version 4.80.0