QID 983776
QID 983776: Nodejs (npm) Security Update for glance (GHSA-7375-vjr2-3g7w)
Versions of `glance` before 3.0.8 are vulnerable to Stored Cross-Site Scripting (XSS). This is only exploitable if the attacker is able to control the name of a file that is served by the `glance` package.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-7375-vjr2-3g7w for updates pertaining to this vulnerability.
Vendor References
- GHSA-7375-vjr2-3g7w -
github.com/advisories/GHSA-7375-vjr2-3g7w
CVEs related to QID 983776
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-7375-vjr2-3g7w | glance |
|