Description
glance node module before 3.0.4 suffers from a Path Traversal vulnerability due to lack of validation of path passed to it, which allows a malicious user to read content of any file with known path.
Remediation
References
https://github.com/jarofghosts/glance/commit/8cfd88e44ebd3f07e3a2eaf376a3e758b6c4ca19
https://hackerone.com/reports/310106
Related Vulnerabilities
CVE-2019-13173 Vulnerability in maven package org.webjars:fstream
CVE-2020-8137 Vulnerability in maven package org.webjars.npm:uppy
CVE-2017-12611 Vulnerability in maven package org.apache.struts:struts2-core
CVE-2022-2047 Vulnerability in maven package org.eclipse.jetty:jetty-http
CVE-2020-7740 Vulnerability in npm package node-pdf-generator