Versions of the package glance before 3.0.9 are vulnerable to Directory Traversal that allows users to read files outside the public root directory. This is related to but distinct from the vulnerability reported in [CVE-2018-3715](https://security.snyk.io/vuln/npm:glance:20180129).
Metrics
Affected Vendors & Products
References
History
Fri, 21 Mar 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: snyk
Published: 2023-02-13T05:00:01.128Z
Updated: 2025-03-21T14:52:00.741Z
Reserved: 2022-02-24T11:58:27.018Z
Link: CVE-2022-25937
Updated: 2024-08-03T04:49:44.550Z
Status : Modified
Published: 2023-02-13T05:15:12.807
Modified: 2025-03-21T15:15:37.517
Link: CVE-2022-25937
No data.