Lucene search

K
osvGoogleOSV:GHSA-2X4Q-6JFV-8H9H
HistoryJul 26, 2018 - 2:53 p.m.

Path Traversal in glance

2018-07-2614:53:14
Google
osv.dev
10

EPSS

0.001

Percentile

31.9%

Versions of glance before 3.0.4 are vulnerable to a Path Traversal vulnerability due to lack of validation of path passed to it, which allows a malicious user to read content of any file with known path.

Recommendation

Update to version 3.0.4 or later.

EPSS

0.001

Percentile

31.9%