Description
Information exposure through the directory listing in npm's harp module allows to access files that are supposed to be ignored according to the harp server rules.Vulnerable versions are <= 0.29.0 and no fix was applied to our knowledge.
Remediation
References
https://hackerone.com/reports/453820
Related Vulnerabilities
CVE-2020-8203 Vulnerability in maven package org.webjars:lodash
CVE-2021-3597 Vulnerability in maven package io.undertow:undertow-core
CVE-2022-1243 Vulnerability in npm package urijs
CVE-2018-16330 Vulnerability in maven package org.webjars.bowergithub.pandao:editor.md
CVE-2021-23358 Vulnerability in maven package org.webjars.npm:underscore