Description
Information exposure through the directory listing in npm's harp module allows to access files that are supposed to be ignored according to the harp server rules.Vulnerable versions are <= 0.29.0 and no fix was applied to our knowledge.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2019-0496 | Information exposure through the directory listing in npm's harp module allows to access files that are supposed to be ignored according to the harp server rules.Vulnerable versions are <= 0.29.0 and no fix was applied to our knowledge. |
Github GHSA |
GHSA-46hv-7769-j7rx | Unauthorized File Access in harp |
References
| Link | Providers |
|---|---|
| https://hackerone.com/reports/453820 |
|
History
No history.
Status: PUBLISHED
Assigner: hackerone
Published:
Updated: 2024-08-04T19:54:53.483Z
Reserved: 2019-01-04T00:00:00.000Z
Link: CVE-2019-5437
No data.
Status : Modified
Published: 2019-05-10T22:29:00.750
Modified: 2024-11-21T04:44:56.097
Link: CVE-2019-5437
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA