Information exposure through the directory listing in npm's harp module allows to access files that are supposed to be ignored according to the harp server rules.Vulnerable versions are <= 0.29.0 and no fix was applied to our knowledge.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| harp(npm) | 0 | 0.40.2 | N/A |
CVSS Metrics