MEDIUM6.1
GHSA-7375-vjr2-3g7w
Cross-Site Scripting in glance
Quick fix
GHSA-7375-vjr2-3g7w — glance: upgrade to the fixed version with the command below.
npm install glance@3.0.8Details
Versions of `glance` before 3.0.8 are vulnerable to Stored Cross-Site Scripting (XSS). This is only exploitable if the attacker is able to control the name of a file that is served by the `glance` package.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2018-3748[ADVISORY]
- https://github.com/jarofghosts/glance/commit/cdc68bb68d785343ddb829f1adc130cdd6169533[WEB]
- https://hackerone.com/reports/310133[WEB]
- https://github.com/advisories/GHSA-7375-vjr2-3g7w[ADVISORY]
- https://github.com/jarofghosts/glance[PACKAGE]
- https://www.npmjs.com/advisories/610[WEB]