CVE-2019-5437
PoC —CVSS 3.0
5.3 medium
EPSS
1%p69
Published
()
Modified
Description
Information exposure through the directory listing in npm's harp module allows to access files that are supposed to be ignored according to the harp server rules.Vulnerable versions are <= 0.29.0 and no fix was applied to our knowledge.
- Vendors
- harpjs
- Products
- harp
- Weakness
- CWE-548, CWE-200
- Vector
- CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
In the news0 stories
No ingested article mentions this CVE yet.