GHSA-vw7g-jq9m-3q9v

Suggest an improvement
Source
https://github.com/advisories/GHSA-vw7g-jq9m-3q9v
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/09/GHSA-vw7g-jq9m-3q9v/GHSA-vw7g-jq9m-3q9v.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-vw7g-jq9m-3q9v
Published
2020-09-02T18:23:35Z
Modified
2020-08-31T18:36:38Z
Summary
Unauthorized File Access in glance
Details

Versions of glance prior to 3.0.7 are vulnerable to Unauthorized File Access. The package provides a --nodot option meant to hide files and directories with names that begin with a ., such as .git but fails to hide files inside a folder that begins with ..

Recommendation

Upgrade to version 3.0.7 or later.

Database specific
{
    "cwe_ids":  [],
    "github_reviewed":  true,
    "github_reviewed_at":  "2020-08-31T18:36:38Z",
    "nvd_published_at":  null,
    "severity":  "MODERATE"
}
References

Affected packages

npm / glance

Package

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
3.0.7

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/09/GHSA-vw7g-jq9m-3q9v/GHSA-vw7g-jq9m-3q9v.json"