Versions of the package glance before 3.0.9 are vulnerable to Directory Traversal that allows users to read files outside the public root directory. This is related to but distinct from the vulnerability reported in [CVE-2018-3715](https://security.snyk.io/vuln/npm:glance:20180129).
References
Link | Resource |
---|---|
https://github.com/jarofghosts/glance/commit/8cecfe90286e0c45a5494067f1b592d0ccfeabac | Patch |
https://security.snyk.io/vuln/SNYK-JS-GLANCE-3318395 | Exploit Third Party Advisory |
https://github.com/jarofghosts/glance/commit/8cecfe90286e0c45a5494067f1b592d0ccfeabac | Patch |
https://security.snyk.io/vuln/SNYK-JS-GLANCE-3318395 | Exploit Third Party Advisory |
Configurations
History
21 Nov 2024, 06:53
Type | Values Removed | Values Added |
---|---|---|
References | () https://github.com/jarofghosts/glance/commit/8cecfe90286e0c45a5494067f1b592d0ccfeabac - Patch | |
References | () https://security.snyk.io/vuln/SNYK-JS-GLANCE-3318395 - Exploit, Third Party Advisory |
07 Nov 2023, 03:44
Type | Values Removed | Values Added |
---|---|---|
Summary | Versions of the package glance before 3.0.9 are vulnerable to Directory Traversal that allows users to read files outside the public root directory. This is related to but distinct from the vulnerability reported in [CVE-2018-3715](https://security.snyk.io/vuln/npm:glance:20180129). |
Information
Published : 2023-02-13 05:15
Updated : 2024-11-21 06:53
NVD link : CVE-2022-25937
Mitre link : CVE-2022-25937
CVE.ORG link : CVE-2022-25937
JSON object : View
Products Affected
glance_project
- glance
CWE
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')