Headline
GHSA-3hjh-5hgx-f5wh: Path traversal vulnerability in glance
Versions of the package glance before 3.0.9 are vulnerable to Directory Traversal that allows users to read files outside the public root directory. This is related to but distinct from the vulnerability reported in CVE-2018-3715.
Path traversal vulnerability in glance
Moderate severity GitHub Reviewed Published Feb 13, 2023 to the GitHub Advisory Database • Updated Feb 14, 2023
Related news
CVE-2022-25937: Fix path traversal vulnerability · jarofghosts/glance@8cecfe9
Versions of the package glance before 3.0.9 are vulnerable to Directory Traversal that allows users to read files outside the public root directory. This is related to but distinct from the vulnerability reported in [CVE-2018-3715](https://security.snyk.io/vuln/npm:glance:20180129).