VYPR

Harp

by Harpjs

CVEs (2)

  • CVE-2019-5438MedMay 10, 2019
    risk 0.35cvss 5.3epss 0.01

    Path traversal using symlink in npm harp module versions <= 0.29.0.

  • CVE-2019-5437MedMay 10, 2019
    risk 0.28cvss 5.3epss 0.01

    Information exposure through the directory listing in npm's harp module allows to access files that are supposed to be ignored according to the harp server rules.Vulnerable versions are <= 0.29.0 and no fix was applied to our knowledge.