Cross-Site Scripting in glance
Moderate severity
GitHub Reviewed
Published
Sep 27, 2018
to the GitHub Advisory Database
•
Updated Jan 9, 2023
Description
Published to the GitHub Advisory Database
Sep 27, 2018
Reviewed
Jun 16, 2020
Last updated
Jan 9, 2023
Versions of
glance
before 3.0.8 are vulnerable to Stored Cross-Site Scripting (XSS). This is only exploitable if the attacker is able to control the name of a file that is served by theglance
package.References