Snyk

Snyk Cli

5 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.02%
  • Veröffentlicht 26.06.2025 05:15:23
  • Zuletzt bearbeitet 09.07.2025 17:53:54

Versions of the package snyk before 1.1297.3 are vulnerable to Insertion of Sensitive Information into Log File through local Snyk CLI debug logs. Container Registry credentials provided via environment variables or command line arguments can be expo...

  • EPSS 0.05%
  • Veröffentlicht 23.10.2024 19:15:19
  • Zuletzt bearbeitet 30.10.2024 14:54:53

The package Snyk CLI before 1.1294.0 is vulnerable to Code Injection when scanning an untrusted PHP project. The vulnerability can be triggered if Snyk test is run inside the untrusted project due to the improper handling of the current working direc...

  • EPSS 0.05%
  • Veröffentlicht 23.10.2024 19:15:19
  • Zuletzt bearbeitet 30.10.2024 13:46:31

The package Snyk CLI before 1.1294.0 is vulnerable to Code Injection when scanning an untrusted Gradle project. The vulnerability can be triggered if Snyk test is run inside the untrusted project due to the improper handling of the current working di...

Exploit
  • EPSS 1.2%
  • Veröffentlicht 30.11.2022 13:15:10
  • Zuletzt bearbeitet 25.04.2025 15:15:30

The package snyk before 1.1064.0; the package snyk-mvn-plugin before 2.31.3; the package snyk-gradle-plugin before 3.24.5; the package @snyk/snyk-cocoapods-plugin before 2.5.3; the package snyk-sbt-plugin before 2.16.2; the package snyk-python-plugin...

Exploit
  • EPSS 1.46%
  • Veröffentlicht 30.11.2022 13:15:10
  • Zuletzt bearbeitet 24.04.2025 20:15:22

The package snyk before 1.1064.0 are vulnerable to Code Injection when analyzing a project. An attacker who can convince a user to scan a malicious project can include commands in a build file such as build.gradle or gradle-wrapper.jar, which will be...