Description
Versions of the package glance before 3.0.9 are vulnerable to Directory Traversal that allows users to read files outside the public root directory. This is related to but distinct from the vulnerability reported in [CVE-2018-3715](https://security.snyk.io/vuln/npm:glance:20180129).
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-0612 | Versions of the package glance before 3.0.9 are vulnerable to Directory Traversal that allows users to read files outside the public root directory. This is related to but distinct from the vulnerability reported in [CVE-2018-3715](https://security.snyk.io/vuln/npm:glance:20180129). |
Github GHSA |
GHSA-3hjh-5hgx-f5wh | Path traversal vulnerability in glance |
References
History
Fri, 21 Mar 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: snyk
Published:
Updated: 2025-03-21T14:52:00.741Z
Reserved: 2022-02-24T11:58:27.018Z
Link: CVE-2022-25937
Updated: 2024-08-03T04:49:44.550Z
Status : Modified
Published: 2023-02-13T05:15:12.807
Modified: 2025-03-21T15:15:37.517
Link: CVE-2022-25937
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA