Description
Path traversal using symlink in npm harp module versions <= 0.29.0.
Remediation
References
https://hackerone.com/reports/530289
Related Vulnerabilities
CVE-2023-3308 Vulnerability in maven package com.whaleal.icefrog:icefrog-all
CVE-2019-10352 Vulnerability in maven package org.jenkins-ci.main:jenkins-core
CVE-2022-23496 Vulnerability in maven package nl.basjes.parse.useragent:yauaa-snowflake
CVE-2018-20059 Vulnerability in maven package ro.pippo:pippo-jaxb