{"id":"CVE-2019-5437","aliases":[],"url":"https://o3.security/vulnerability/CVE-2019-5437","summary":"Unauthorized File Access in harp","details":"Affected versions of `harp` are vulnerable to Unauthorized File Access. The package states that it ignores files and directories with names that start with an underscore, such as `_secret-folder`. If the underscore character is URL encoded the server delivers the file.\n\n## Recommendation\n\nUpgrade to version `0.40.2` or later.","published":"2019-06-13T16:12:22Z","modified":"2023-11-08T04:01:36.165453Z","cvss":{"score":5.3,"severity":"MEDIUM","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":1,"affectedPackages":[{"ecosystem":"npm","name":"harp","fixedVersion":"0.40.2"}],"fix":{"url":"https://github.com/sintaxi/harp/commit/1ec790baeeb2bfdb4584f1998af3d10a8fa31210","label":"sintaxi/harp@1ec790b"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2019-5437"},{"type":"WEB","url":"https://github.com/sintaxi/harp/commit/1ec790baeeb2bfdb4584f1998af3d10a8fa31210"},{"type":"WEB","url":"https://hackerone.com/reports/453820"},{"type":"WEB","url":"https://www.npmjs.com/advisories/807"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2023-11-08T04:01:36.165453Z"}}