Versions of the package glance before 3.0.9 are vulnerable to Directory Traversal that allows users to read files outside the public root directory. This is related to but distinct from the vulnerability reported in [CVE-2018-3715](https://security.snyk.io/vuln/npm:glance:20180129).
References
Link | Resource |
---|---|
https://github.com/jarofghosts/glance/commit/8cecfe90286e0c45a5494067f1b592d0ccfeabac | Patch |
https://security.snyk.io/vuln/SNYK-JS-GLANCE-3318395 | Exploit Third Party Advisory |
Configurations
History
No history.
Information
Published : 2023-02-13 05:15
Updated : 2023-11-07 03:44
NVD link : CVE-2022-25937
Mitre link : CVE-2022-25937
CVE.ORG link : CVE-2022-25937
JSON object : View
Products Affected
glance_project
- glance
CWE
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')