Information disclosure in Broker - CVE-2020-7648
Published: June 5, 2020
Broker
Snyk Ltd.
Description
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to excessive data output by the application. A remote user with access to Snyk's internal network can append the URL with a fragment identifier and a whitelisted path e.g. "#package.json" and gain unauthorized access to sensitive information on the system.