CVE-2019-5437
UnknownEPSS 1.31%
Last modified
CVE-2019-5437 is a vulnerability of currently unknown severity. Information exposure through the directory listing in npm's harp module allows to access files that are supposed to be ignored according to the harp server rules.Vulnerable versions are <= 0.29.0 and no fix was applied to our knowledge.. EPSS estimates a 1.31% chance of exploitation in the next 30 days.
Description
Information exposure through the directory listing in npm's harp module allows to access files that are supposed to be ignored according to the harp server rules.Vulnerable versions are <= 0.29.0 and no fix was applied to our knowledge.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Harpjs | Harp | <= 0.29.0 |
References
- https://hackerone.com/reports/453820Exploit, Third Party Advisory
- https://hackerone.com/reports/453820Exploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2019-5437?
Information exposure through the directory listing in npm's harp module allows to access files that are supposed to be ignored according to the harp server rules.Vulnerable versions are <= 0.29.0 and no fix was applied to our knowledge.
How severe is CVE-2019-5437?
Severity scoring for CVE-2019-5437 is pending analysis. The EPSS model estimates a 1.31% probability of exploitation in the next 30 days.
How do I fix CVE-2019-5437?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2019
- CVE-2019-5431This vulnerability was caused by an incomplete fix to CVE-20…5.4
- CVE-2019-5432A specifically malformed MQTT Subscribe packet crashes MQTT …7.5
- CVE-2019-5433A user having access to the UI of a Revive Adserver instance…
- CVE-2019-5434An attacker could send a specifically crafted payload to the…
- CVE-2019-5435An integer overflow in curl's URL API results in a buffer ov…
- CVE-2019-5436A heap buffer overflow in the TFTP receiving code allows for…7.8
- CVE-2019-5438Path traversal using symlink in npm harp module versions <= …5.3
- CVE-2019-5439A Buffer Overflow in VLC Media Player < 3.0.7 causes a crash…
- CVE-2019-5440Use of cryptographically weak PRNG in the password recovery …
- CVE-2019-5441Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2019-5442XML Entity Expansion (Billion Laughs Attack) on Pippo 1.12.0…7.5
- CVE-2019-5443A non-privileged user or program can put code and a config f…7.8
Are you affected by CVE-2019-5437?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
