Description
Information exposure through the directory listing in npm's harp module allows to access files that are supposed to be ignored according to the harp server rules.Vulnerable versions are <= 0.29.0 and no fix was applied to our knowledge.
Remediation
References
https://hackerone.com/reports/453820
Related Vulnerabilities
CVE-2021-23358 Vulnerability in maven package org.webjars.npm:underscore
CVE-2022-37199 Vulnerability in maven package com.jflyfox:jflyfox_jfinal
CVE-2022-26585 Vulnerability in maven package net.mingsoft:ms-mcms
CVE-2020-7692 Vulnerability in maven package com.google.oauth-client:google-oauth-client
CVE-2022-45688 Vulnerability in maven package cn.hutool:hutool-json