Junglewise Threat Intelligence

CVE-2022-25937: jarofghosts glance path traversal in static file server

CVE-2022-25937 · Severity: low · CVSS 3.1 · Published 2023-02-13

Technologies: glance (npm). Vendors: npm.

Executive brief

glance is a lightweight HTTP server used for serving static files. A security flaw allows an attacker to bypass directory restrictions and access files on the host system that should be private. This could lead to the exposure of sensitive configuration files, source code, or other data stored outside the intended public folder.

Technical details

A path traversal vulnerability (CWE-22) exists in glance versions prior to 3.0.9. The issue stems from an incomplete fix for a previous traversal bug (CVE-2018-3715), where the application fails to properly validate that requested paths remain within the boundaries of the configured public directory. An attacker can use '..' sequences in a URL to access sibling directories that share a partial name or similar path structure with the public root. Exploitation requires network access to the running glance server and can result in unauthorized disclosure of local files. The vulnerability is resolved in version 3.0.9.

Affected products

  • jarofghosts glance < 3.0.9

Timeline

  • 2022-09-26: disclosed: Initial discovery and PoC shared via GitHub Gist
  • 2023-02-12: advisory: Snyk published advisory SNYK-JS-GLANCE-3318395
  • 2023-02-13: patched: Version 3.0.9 released with fix

References

Related threats