MEDIUM
Versions of the package glance before 3.0.9 are vulnerable to Directory Traversal that allows users to read files outside the public root directory
Published Feb 13, 2023
6.5
MEDIUMCVSS 3.1
EPSS 1.11%
Description
Versions of the package glance before 3.0.9 are vulnerable to Directory Traversal that allows users to read files outside the public root directory. This is related to but distinct from the vulnerability reported in [CVE-2018-3715](https://security.snyk.io/vuln/npm:glance:20180129).
Affected products
- Vendor n/a Product Glance Defaultn/a
- Version 0StatusaffectedConstraints<3.0.9
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| n/a | Glance | n/a |
|
- < 3.0.9
No data.
No Red Hat product state for this CVE.
glance
npm
Introduced 0 Fixed 3.0.9
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| npm | glance | 0 | 3.0.9 |
Remediation
No remediation recorded yet.
Weaknesses (1)
References (6)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-0612 Advisory
- https://gist.github.com/lirantal/c8cfb0398c78e558b7d4ac02aae67809
- https://github.com/advisories/GHSA-3hjh-5hgx-f5wh Advisory
- https://github.com/jarofghosts/glance/commit/8cecfe90286e0c45a5494067f1b592d0ccfeabac Patch
- https://nvd.nist.gov/vuln/detail/CVE-2022-25937
- https://security.snyk.io/vuln/SNYK-JS-GLANCE-3318395 ExploitThird Party Advisory
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner snyk
Published Feb 13, 2023
Updated Mar 21, 2025
Reserved Feb 24, 2022
Link CVE-2022-25937
CISA Vulnrichment
Updated Mar 21, 2025
ENISA EUVD
EUVD-2023-0612 GHSA-3HJH-5HGX-F5WH Assigner snyk
Published Feb 13, 2023
Updated Mar 21, 2025
Exploited since n/a
Link EUVD-2023-0612