MEDIUM
Path traversal using symlink in npm harp module versions <= 0.29.0
Published May 10, 2019
5.3
MEDIUMCVSS 3.1
EPSS 1.49%
Description
Path traversal using symlink in npm harp module versions <= 0.29.0.
Affected products
- Vendor n/a Product Harp Defaultn/a
- Version Not fixedStatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| n/a | Harp | n/a |
|
No data.
No Red Hat product state for this CVE.
harp
npm
Introduced 0 Fixed 0.40.3
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| npm | harp | 0 | 0.40.3 |
Remediation
No remediation recorded yet.
Weaknesses (2)
References (5)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-0510 Advisory
- https://github.com/advisories/GHSA-6fmm-47qc-p4m4 Advisory
- https://hackerone.com/reports/530289 x_refsource_MISCExploitThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2019-5438
- https://www.npmjs.com/advisories/816
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-0510 | Advisory | |
| https://github.com/advisories/GHSA-6fmm-47qc-p4m4 | Advisory | |
| https://hackerone.com/reports/530289 | x_refsource_MISCExploitThird Party Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2019-5438 | ||
| https://www.npmjs.com/advisories/816 |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner hackerone
Published May 10, 2019
Updated Aug 4, 2024
Reserved Jan 4, 2019
Link CVE-2019-5438
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2019-0510 GHSA-6FMM-47QC-P4M4 Assigner hackerone
Published May 10, 2019
Updated Aug 4, 2024
Exploited since n/a
Link EUVD-2019-0510