Executive brief
Snyk Broker is a proxy service used by organizations to securely connect Snyk's vulnerability scanning platform to internal Git repositories and development tools. When debug logging is enabled, the application inadvertently logs sensitive private keys and credentials, making them accessible to anyone with access to the logs. This exposure could allow attackers to compromise Git repositories, CI/CD pipelines, and other critical development infrastructure.
Technical details
The vulnerability is an information exposure issue (CWE-532) in the Snyk Broker application where private keys are logged when the application logging level is set to DEBUG. The vulnerable component is the logging system, which fails to redact or suppress sensitive authentication credentials. An attacker with access to application logs (local file access, centralized logging systems, or container logs) can extract private keys used for authentication. The attack vector is local and does not require network access or user interaction. Versions before 4.73.1 are affected; the fix is to upgrade to version 4.73.1 or later, which implements proper log sanitization.
Affected products
- Snyk Broker before 4.73.1
Timeline
- 2020-05-28: disclosed
- 2020-06-03: advisory
- 2020-06-03: patched: Version 4.73.1 released with fix