QID 982366
QID 982366: Nodejs (npm) Security Update for harp (GHSA-46hv-7769-j7rx)
Affected versions of `harp` are vulnerable to Unauthorized File Access. The package states that it ignores files and directories with names that start with an underscore, such as `_secret-folder`. If the underscore character is URL encoded the server delivers the file.
## Recommendation
Upgrade to version `0.40.2` or later.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-46hv-7769-j7rx for updates pertaining to this vulnerability.
Vendor References
- GHSA-46hv-7769-j7rx -
github.com/advisories/GHSA-46hv-7769-j7rx
CVEs related to QID 982366
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-46hv-7769-j7rx | harp |
|