Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-46hv-7769-j7rx

Опубликовано: 13 июн. 2019
Источник: github
Github: Прошло ревью
CVSS3: 5.3

Описание

Unauthorized File Access in harp

Affected versions of harp are vulnerable to Unauthorized File Access. The package states that it ignores files and directories with names that start with an underscore, such as _secret-folder. If the underscore character is URL encoded the server delivers the file.

Recommendation

Upgrade to version 0.40.2 or later.

Пакеты

Наименование

harp

npm
Затронутые версииВерсия исправления

< 0.40.2

0.40.2

EPSS

Процентиль: 45%
0.00222
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-548

Связанные уязвимости

CVSS3: 5.3
nvd
больше 6 лет назад

Information exposure through the directory listing in npm's harp module allows to access files that are supposed to be ignored according to the harp server rules.Vulnerable versions are <= 0.29.0 and no fix was applied to our knowledge.

EPSS

Процентиль: 45%
0.00222
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-548