VDB
Sign up
MEDIUM6.1

GHSA-7375-vjr2-3g7w

Cross-Site Scripting in glance

Quick fix

GHSA-7375-vjr2-3g7w — glance: upgrade to the fixed version with the command below.

npm install glance@3.0.8

Details

Versions of `glance` before 3.0.8 are vulnerable to Stored Cross-Site Scripting (XSS). This is only exploitable if the attacker is able to control the name of a file that is served by the `glance` package.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/glance
Introduced in: 0Fixed in: 3.0.8
Fixnpm install glance@3.0.8

References