Description
Information exposure through the directory listing in npm's harp module allows to access files that are supposed to be ignored according to the harp server rules.Vulnerable versions are <= 0.29.0 and no fix was applied to our knowledge.
Remediation
References
https://hackerone.com/reports/453820
Related Vulnerabilities
CVE-2022-34114 Vulnerability in maven package io.dataease:dataease-plugin-common
CVE-2023-24162 Vulnerability in maven package cn.hutool:hutool-all
CVE-2022-41935 Vulnerability in maven package org.xwiki.platform:xwiki-platform-livetable-ui
CVE-2018-1000536 Vulnerability in npm package medis
CVE-2021-45105 Vulnerability in maven package org.apache.logging.log4j:log4j-core