Description
All versions of snyk-broker after 4.72.0 including and before 4.73.1 are vulnerable to Arbitrary File Read. It allows arbitrary file reads to users with access to Snyk's internal network of any files ending in the following extensions: yaml, yml or json.
Remediation
References
https://snyk.io/vuln/SNYK-JS-SNYKBROKER-570609
https://updates.snyk.io/snyk-broker-security-fixes-152338
Related Vulnerabilities
CVE-2020-9482 Vulnerability in maven package org.apache.nifi.registry:nifi-registry-web-api
CVE-2017-12161 Vulnerability in maven package org.keycloak:keycloak-core
CVE-2019-10754 Vulnerability in maven package org.apereo.cas:cas-server-core-services-api
CVE-2021-25924 Vulnerability in maven package cd.go.plugin:go-plugin-api
CVE-2021-28168 Vulnerability in maven package org.glassfish.jersey.core:jersey-common