ZeroHour

CVE-2019-5437

PoC
CVSS 3.0
5.3 medium
EPSS
1%p69
Published
()
Modified
Description

Information exposure through the directory listing in npm's harp module allows to access files that are supposed to be ignored according to the harp server rules.Vulnerable versions are <= 0.29.0 and no fix was applied to our knowledge.

Vendors
harpjs
Products
harp
Weakness
CWE-548, CWE-200
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

In the news

No ingested article mentions this CVE yet.