Description
Affected versions of harp are vulnerable to Unauthorized File Access. The package states that it ignores files and directories with names that start with an underscore, such as _secret-folder. If the underscore character is URL encoded the server delivers the file.
Recommendation
Update the harp package to the latest compatible version. Followings are version details:
- Affected version(s): < 0.40.2
- Patched version(s): 0.40.2
References
- GHSA-46hv-7769-j7rx
- hackerone.com
- www.npmjs.com
- CVE-2019-5437
- CWE-548
- CAPEC-310
- OWASP 2021-A1
- OWASP 2021-A6
Related Issues
- Unauthorized File Access in harp (GHSA-6fmm-47qc-p4m4) - CVE-2019-5438
- Cross-Site Scripting in http-file-server - CVE-2019-5458
- Path Traversal in http-file-server - CVE-2019-5447
- TaffyDB can allow access to any data items in the DB - CVE-2019-10790
- Tags:
- npm
- harp
Anything's wrong? Let us know Last updated on September 07, 2023