VDB
Sign up
MEDIUM6.5

GHSA-3hjh-5hgx-f5wh

Path traversal vulnerability in glance

Quick fix

GHSA-3hjh-5hgx-f5wh — glance: upgrade to the fixed version with the command below.

npm install glance@3.0.9

Details

Versions of the package glance before 3.0.9 are vulnerable to Directory Traversal that allows users to read files outside the public root directory. This is related to but distinct from the vulnerability reported in [CVE-2018-3715](https://security.snyk.io/vuln/npm:glance:20180129).

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/glance
Introduced in: 0Fixed in: 3.0.9
Fixnpm install glance@3.0.9

References