Medium severity5.3NVD Advisory· Published Jun 3, 2021· Updated Jun 17, 2026
CVE-2020-28469
CVE-2020-28469
Description
This affects the package glob-parent before 5.1.2. The enclosure regex used to check for strings ending in enclosure containing path separator.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
glob-parentnpm | >= 4.0.0, < 5.1.2 | 5.1.2 |
Affected products
13- cpe:2.3:a:oracle:communications_cloud_native_core_policy:1.14.0:*:*:*:*:*:*:*
- glob-parent/glob-parentdescription
- ghsa-coords10 versionspkg:npm/glob-parentpkg:rpm/almalinux/nodejs-packagingpkg:rpm/almalinux/nodejspkg:rpm/almalinux/nodejs-develpkg:rpm/almalinux/nodejs-docspkg:rpm/almalinux/nodejs-full-i18npkg:rpm/almalinux/nodejs-nodemonpkg:rpm/almalinux/npmpkg:rpm/almalinux/nodejs-libspkg:bitnami/gulp
>= 4.0.0, < 5.1.2+ 9 more
- (no CPE)range: >= 4.0.0, < 5.1.2
- (no CPE)range: < 25-1.module_el8.5.0+246+05401605
- (no CPE)range: < 1:16.13.1-3.module_el8.5.0+2605+45d748af
- (no CPE)range: < 1:16.13.1-3.module_el8.5.0+2605+45d748af
- (no CPE)range: < 1:16.13.1-3.module_el8.5.0+2605+45d748af
- (no CPE)range: < 1:16.13.1-3.module_el8.5.0+2605+45d748af
- (no CPE)range: < 2.0.15-1.module_el8.6.0+2904+f21ad6f4
- (no CPE)range: < 1:8.1.2-1.16.13.1.3.module_el8.5.0+2605+45d748af
- (no CPE)range: < 1:16.16.0-1.el9_0
- (no CPE)range: < 5.1.2
Patches
Vulnerability mechanics
References
11- github.com/gulpjs/glob-parent/pull/36nvdPatchThird Party AdvisoryWEB
- www.oracle.com/security-alerts/cpujan2022.htmlnvdPatchThird Party AdvisoryWEB
- snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWERGITHUBES128-1059093nvdExploitThird Party AdvisoryWEB
- snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-1059092nvdExploitThird Party AdvisoryWEB
- snyk.io/vuln/SNYK-JS-GLOBPARENT-1016905nvdExploitThird Party AdvisoryWEB
- github.com/advisories/GHSA-ww39-953v-wcq6ghsaADVISORY
- github.com/gulpjs/glob-parent/releases/tag/v5.1.2nvdRelease NotesThird Party AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2020-28469ghsaADVISORY
- github.com/gulpjs/glob-parent/blob/6ce8d11f2f1ed8e80a9526b1dc8cf3aa71f43474/index.js%23L9nvdBroken LinkWEB
- github.com/gulpjs/glob-parent/commit/4a80667c69355c76a572a5892b0f133c8e1f457eghsaWEB
- github.com/gulpjs/glob-parent/pull/36/commits/c6db86422a9731d4f3d332ce4a81c27ea6b0ee46ghsaWEB
News mentions
0No linked articles in our index yet.