MEDIUM6.5
GHSA-2x4q-6jfv-8h9h
Path Traversal in glance
Quick fix
GHSA-2x4q-6jfv-8h9h — glance: upgrade to the fixed version with the command below.
npm install glance@3.0.4Details
Versions of `glance` before 3.0.4 are vulnerable to a Path Traversal vulnerability due to lack of validation of path passed to it, which allows a malicious user to read content of any file with known path.
## Recommendation
Update to version 3.0.4 or later.
Are you affected?
Enter the version of the package you're using.