Information exposure through the directory listing in npm's harp module allows to access files that are supposed to be ignored according to the harp server rules.Vulnerable versions are <= 0.29.0 and no fix was applied to our knowledge.
References
Link | Resource |
---|---|
https://hackerone.com/reports/453820 | Exploit Third Party Advisory |
Configurations
Information
Published : 2019-05-10 15:29
Updated : 2019-10-09 16:50
NVD link : CVE-2019-5437
Mitre link : CVE-2019-5437
JSON object : View
CWE
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor
Products Affected
harpjs
- harp