GMS-2020-725: Unauthorized File Access in glance
Versions of glance
prior to 3.0.7 are vulnerable to Unauthorized File Access. The package provides a --nodot
option meant to hide files and directories with names that begin with a .
, such as .git
but fails to hide files inside a folder that begins with .
.
Recommendation
Upgrade to version 3.0.7 or later.
References
Detect and mitigate GMS-2020-725 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →