Versions of the package glance before 3.0.9 are vulnerable to Directory Traversal that allows users to read files outside the public root directory. This is related to but distinct from the vulnerability reported in [CVE-2018-3715](https://security.snyk.io/vuln/npm:glance:20180129).
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-0612 | Versions of the package glance before 3.0.9 are vulnerable to Directory Traversal that allows users to read files outside the public root directory. This is related to but distinct from the vulnerability reported in [CVE-2018-3715](https://security.snyk.io/vuln/npm:glance:20180129). |
Github GHSA |
GHSA-3hjh-5hgx-f5wh | Path traversal vulnerability in glance |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Fri, 21 Mar 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: snyk
Published:
Updated: 2025-03-21T14:52:00.741Z
Reserved: 2022-02-24T11:58:27.018Z
Link: CVE-2022-25937
Updated: 2024-08-03T04:49:44.550Z
Status : Modified
Published: 2023-02-13T05:15:12.807
Modified: 2025-03-21T15:15:37.517
Link: CVE-2022-25937
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA