Description
Information exposure through the directory listing in npm's harp module allows to access files that are supposed to be ignored according to the harp server rules.Vulnerable versions are <= 0.29.0 and no fix was applied to our knowledge.
Remediation
References
https://hackerone.com/reports/453820
Related Vulnerabilities
CVE-2021-23574 Vulnerability in npm package js-data
CVE-2022-25645 Vulnerability in maven package org.webjars.npm:dset
CVE-2018-16491 Vulnerability in maven package org.webjars.npm:node.extend
CVE-2023-49377 Vulnerability in maven package com.jfinal:jfinal
CVE-2021-25646 Vulnerability in maven package org.apache.druid:druid-core