CVE-2019-5437

MEDIUM

npm harp <0.29.0 - Info Disclosure

Title source: llm

Description

Information exposure through the directory listing in npm's harp module allows to access files that are supposed to be ignored according to the harp server rules.Vulnerable versions are <= 0.29.0 and no fix was applied to our knowledge.

Scores

CVSS v3 5.3
EPSS 0.0022
EPSS Percentile 44.5%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Classification

CWE
CWE-548 CWE-200
Status published

Affected Products (2)

harpjs/harp < 0.29.0
npm/harp < 0.40.2npm

Timeline

Published May 10, 2019
Tracked Since Feb 18, 2026