Vulnerability CVE-2022-25937


Published: 2023-02-13

Description:
Versions of the package glance before 3.0.9 are vulnerable to Directory Traversal that allows users to read files outside the public root directory. This is related to but distinct from the vulnerability reported in [CVE-2018-3715](https://security.snyk.io/vuln/npm:glance:20180129).

 References:
https://github.com/jarofghosts/glance/commit/8cecfe90286e0c45a5494067f1b592d0ccfeabac
https://security.snyk.io/vuln/SNYK-JS-GLANCE-3318395

Copyright 2026, cxsecurity.com

 

Back to Top