CVE-2022-25937
Summary
| CVE | CVE-2022-25937 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-02-13 05:15:00 UTC |
| Updated | 2023-11-07 03:44:00 UTC |
| Description | Versions of the package glance before 3.0.9 are vulnerable to Directory Traversal that allows users to read files outside the public root directory. This is related to but distinct from the vulnerability reported in [CVE-2018-3715](https://security.snyk.io/vuln/npm:glance:20180129). |
Risk And Classification
Problem Types: CWE-22
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Glance Project | Glance | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Directory Traversal in glance | CVE-2022-25937 | Snyk | MISC | security.snyk.io | |
| Fix path traversal vulnerability · jarofghosts/glance@8cecfe9 · GitHub | MISC | github.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.