VYPR

snyk

by Rich Harris

npm: snyk

CVEs (4)

  • CVE-2024-48964HigOct 23, 2024
    risk 0.42cvss 7.5epss 0.00

    The package Snyk CLI before 1.1294.0 is vulnerable to Code Injection when scanning an untrusted Gradle project. The vulnerability can be triggered if Snyk test is run inside the untrusted project due to the improper handling of the current working directory name. Snyk recommends…

  • CVE-2024-48963HigOct 23, 2024
    risk 0.42cvss 7.5epss 0.00

    The package Snyk CLI before 1.1294.0 is vulnerable to Code Injection when scanning an untrusted PHP project. The vulnerability can be triggered if Snyk test is run inside the untrusted project due to the improper handling of the current working directory name. Snyk recommends…

  • CVE-2022-24441MedNov 30, 2022
    risk 0.31cvss 5.8epss 0.01

    The package snyk before 1.1064.0 are vulnerable to Code Injection when analyzing a project. An attacker who can convince a user to scan a malicious project can include commands in a build file such as build.gradle or gradle-wrapper.jar, which will be executed with the privileges…

  • CVE-2023-1065MedFeb 28, 2023
    risk 0.00cvss 6.5epss 0.01

    This vulnerability in the Snyk Kubernetes Monitor can result in irrelevant data being posted to a Snyk Organization, which could in turn obfuscate other, relevant, security issues. It does not expose the user of the integration to any direct security risk and no user data can be…