Information exposure through the directory listing in npms harp module allows to access files that are supposed to be ignored according to the harp server rules.Vulnerable versions are <= 0.29.0 and no fix was applied to our knowledge.
The product inappropriately exposes a directory listing with an index of all the resources located inside of the directory.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Harp | Harpjs | * | 0.29.0 (including) |