Versions of the package glance before 3.0.9 are vulnerable to Directory Traversal that allows users to read files outside the public root directory. This is related to but distinct from the vulnerability reported in [CVE-2018-3715](https://security.snyk.io/vuln/npm:glance:20180129).
References
Link | Resource |
---|---|
https://github.com/jarofghosts/glance/commit/8cecfe90286e0c45a5494067f1b592d0ccfeabac | Patch |
https://security.snyk.io/vuln/SNYK-JS-GLANCE-3318395 | Exploit Third Party Advisory |
Configurations
Information
Published : 2023-02-12 21:15
Updated : 2023-02-23 22:35
NVD link : CVE-2022-25937
Mitre link : CVE-2022-25937
JSON object : View
CWE
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Products Affected
glance_project
- glance