Description
Information exposure through the directory listing in npm's harp module allows to access files that are supposed to be ignored according to the harp server rules.Vulnerable versions are <= 0.29.0 and no fix was applied to our knowledge.
Remediation
References
https://hackerone.com/reports/453820
Related Vulnerabilities
CVE-2024-36401 Vulnerability in maven package org.geoserver.web:gs-web-app
CVE-2016-7103 Vulnerability in npm package jquery-ui
CVE-2017-16104 Vulnerability in npm package citypredict.whauwiller
CVE-2020-10244 Vulnerability in maven package dev.paseto:jpaseto-sodium
CVE-2023-26487 Vulnerability in maven package org.webjars.npm:vega