CVE-2020-7653: Information Exposure
(updated )
snyk-broker is vulnerable to Arbitrary File Read. It allows arbitrary file reads for users with access to Snyk’s internal network by creating symlinks to match certain paths.
References
Code Behaviors & Features
Detect and mitigate CVE-2020-7653 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →