Description
Path traversal using symlink in npm harp module versions <= 0.29.0.
Remediation
References
https://hackerone.com/reports/530289
Related Vulnerabilities
CVE-2017-16089 Vulnerability in npm package serverlyr
CVE-2022-23457 Vulnerability in maven package org.owasp.esapi:esapi
CVE-2022-43430 Vulnerability in maven package com.compuware.jenkins:compuware-topaz-for-total-test
CVE-2020-8203 Vulnerability in maven package org.webjars.bower:lodash
CVE-2023-1584 Vulnerability in maven package io.quarkus:quarkus-oidc