Описание
Path Traversal in glance
Versions of glance before 3.0.4 are vulnerable to a Path Traversal vulnerability due to lack of validation of path passed to it, which allows a malicious user to read content of any file with known path.
Recommendation
Update to version 3.0.4 or later.
Пакеты
Наименование
glance
npm
Затронутые версииВерсия исправления
< 3.0.4
3.0.4
Связанные уязвимости
CVSS3: 6.5
nvd
больше 7 лет назад
glance node module before 3.0.4 suffers from a Path Traversal vulnerability due to lack of validation of path passed to it, which allows a malicious user to read content of any file with known path.