MEDIUM6.5
GHSA-3hjh-5hgx-f5wh
Path traversal vulnerability in glance
Quick fix
GHSA-3hjh-5hgx-f5wh — glance: upgrade to the fixed version with the command below.
npm install glance@3.0.9Details
Versions of the package glance before 3.0.9 are vulnerable to Directory Traversal that allows users to read files outside the public root directory. This is related to but distinct from the vulnerability reported in [CVE-2018-3715](https://security.snyk.io/vuln/npm:glance:20180129).
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2022-25937[ADVISORY]
- https://github.com/jarofghosts/glance/commit/8cecfe90286e0c45a5494067f1b592d0ccfeabac[WEB]
- https://gist.github.com/lirantal/c8cfb0398c78e558b7d4ac02aae67809[WEB]
- https://github.com/jarofghosts/glance[PACKAGE]
- https://security.snyk.io/vuln/SNYK-JS-GLANCE-3318395[WEB]