Description
Information exposure through the directory listing in npm's harp module allows to access files that are supposed to be ignored according to the harp server rules.Vulnerable versions are <= 0.29.0 and no fix was applied to our knowledge.
Remediation
References
https://hackerone.com/reports/453820
Related Vulnerabilities
CVE-2020-24807 Vulnerability in npm package socket.io-file
CVE-2020-13955 Vulnerability in maven package org.apache.calcite:calcite-core
CVE-2019-0194 Vulnerability in maven package org.apache.camel:camel-core
CVE-2011-0013 Vulnerability in maven package org.apache.tomcat.embed:tomcat-embed-core
CVE-2021-36373 Vulnerability in maven package org.apache.ant:ant