Description
Affected versions of harp
are vulnerable to Unauthorized File Access. The package states that it ignores files and directories with names that start with an underscore, such as _secret-folder
. If the underscore character is URL encoded the server delivers the file.
Recommendation
Update the harp
package to the latest compatible version. Followings are version details:
- Affected version(s): < 0.40.2
- Patched version(s): 0.40.2
References
- GHSA-46hv-7769-j7rx
- hackerone.com
- www.npmjs.com
- CVE-2019-5437
- CWE-548
- CAPEC-310
- OWASP 2021-A1
- OWASP 2021-A6
Related Issues
- Command Injection Vulnerability - CVE-2021-21315
- Cloudera HUE Account Enumeration - CVE-2016-4947
- Cross-Site Scripting in exceljs - CVE-2018-16459
- Sensitive data exposure in NATS - CVE-2020-26149
- Tags:
- npm
- harp
Anything's wrong? Let us know Last updated on September 07, 2023