Description
Information exposure through the directory listing in npm's harp module allows to access files that are supposed to be ignored according to the harp server rules.Vulnerable versions are <= 0.29.0 and no fix was applied to our knowledge.
Remediation
References
https://hackerone.com/reports/453820
Related Vulnerabilities
CVE-2021-44832 Vulnerability in maven package org.apache.logging.log4j:log4j-core
CVE-2020-7758 Vulnerability in npm package browserless-chrome
CVE-2022-23505 Vulnerability in npm package passport-wsfed-saml2
CVE-2020-28451 Vulnerability in npm package image-tiler
CVE-2022-2564 Vulnerability in maven package org.webjars.npm:mongoose