Junglewise Threat Intelligence

CVE-2018-3748: glance Stored Cross-Site Scripting in filename

CVE-2018-3748 · Severity: low · CVSS 3 · Published 2018-09-27

Technologies: glance (npm). Vendors: npm.

Executive brief

glance is a JavaScript library used to serve and display files. A Stored XSS vulnerability in filename handling allows an attacker who can control file names to inject malicious scripts that execute in the browsers of users viewing those files. This could lead to session hijacking, credential theft, or malware distribution to end users.

Technical details

The vulnerability is a Stored Cross-Site Scripting (XSS) flaw in glance versions before 3.0.8, specifically in how the library handles filenames when serving files. The root cause is improper sanitization or encoding of file names before they are rendered in HTML responses. An attacker who can control or influence the names of files served by the glance package can inject malicious JavaScript payloads into filenames; these payloads are then executed in the browsers of users who access or view those files. The attack requires the attacker to have upload or filesystem access to place files with XSS payloads in their names. The vulnerability was fixed in version 3.0.8.

Affected products

  • jarofghosts glance before 3.0.8

Timeline

  • 2018-09-27: disclosed
  • 2018: patched: fixed in version 3.0.8

References

Related threats