Description
All versions of snyk-broker before 4.80.0 are vulnerable to Arbitrary File Read. It allows arbitrary file reads for users with access to Snyk's internal network by creating symlinks to match whitelisted paths.
Remediation
References
https://snyk.io/vuln/SNYK-JS-SNYKBROKER-570612
https://updates.snyk.io/snyk-broker-security-fixes-152338
Related Vulnerabilities
CVE-2021-23438 Vulnerability in npm package mpath
CVE-2023-37914 Vulnerability in maven package org.xwiki.platform:xwiki-platform-invitation-ui
CVE-2022-25205 Vulnerability in maven package org.jenkins-ci.plugins:dbcharts
CVE-2023-30428 Vulnerability in maven package org.apache.pulsar:pulsar-broker
CVE-2021-44906 Vulnerability in maven package org.webjars.bowergithub.substack:minimist