Description
All versions of snyk-broker after 4.72.0 including and before 4.73.1 are vulnerable to Arbitrary File Read. It allows arbitrary file reads to users with access to Snyk's internal network of any files ending in the following extensions: yaml, yml or json.
Remediation
References
https://snyk.io/vuln/SNYK-JS-SNYKBROKER-570609
https://updates.snyk.io/snyk-broker-security-fixes-152338
Related Vulnerabilities
CVE-2013-2071 Vulnerability in maven package org.apache.tomcat.embed:tomcat-embed-core
CVE-2023-26143 Vulnerability in npm package blamer
CVE-2023-29215 Vulnerability in maven package org.apache.linkis:linkis-engineplugin-jdbc
CVE-2023-24455 Vulnerability in maven package io.jenkins.plugins:visualexpert
CVE-2023-26470 Vulnerability in maven package org.xwiki.platform:xwiki-platform-oldcore