Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Harbor

Harborреестр для хранения Docker образов c открытым исходным кодом.

Релизный цикл, информация об уязвимостях

Продукт: Harbor
Вендор: Linux Foundation

График релизов

2.102.112.122.132.142.1520232024202520262027

Недавние уязвимости Harbor

Количество 82

nvd логотип

CVE-2020-13788

около 6 лет назад

Harbor prior to 2.0.1 allows SSRF with this limitation: an attacker with the ability to edit projects can scan ports of hosts accessible on the Harbor server's intranet.

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2019-19029

больше 6 лет назад

Cloud Native Computing Foundation Harbor prior to 1.8.6 and 1.9.3 allows SQL Injection via user-groups in the VMware Harbor Container Registry for the Pivotal Platform.

CVSS3: 7.2
EPSS: Низкий
nvd логотип

CVE-2019-19026

больше 6 лет назад

Cloud Native Computing Foundation Harbor prior to 1.8.6 and 1.9.3 allows SQL Injection via project quotas in the VMware Harbor Container Registry for the Pivotal Platform.

CVSS3: 4.9
EPSS: Низкий
nvd логотип

CVE-2019-19025

больше 6 лет назад

Cloud Native Computing Foundation Harbor prior to 1.8.6 and 1.9.3 allows CSRF in the VMware Harbor Container Registry for the Pivotal Platform.

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2019-19023

больше 6 лет назад

Cloud Native Computing Foundation Harbor prior to 1.8.6 and 1.9.3 has a Privilege Escalation Vulnerability in the VMware Harbor Container Registry for the Pivotal Platform.

CVSS3: 8.8
EPSS: Низкий
fstec логотип

BDU:2021-02130

больше 6 лет назад

Уязвимость реестра для Docker-контейнеров Harbor, связанная с подделкой межсайтовых запросов, позволяющая нарушителю оказать воздействие на конфиденциальность, целостность и доступность защищаемой информации

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2019-3990

почти 7 лет назад

A User Enumeration flaw exists in Harbor. The issue is present in the "/users" API endpoint. This endpoint is supposed to be restricted to administrators. This restriction is able to be bypassed and information can be obtained about registered users can be obtained via the "search" functionality.

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2019-16919

почти 7 лет назад

Harbor API has a Broken Access Control vulnerability. The vulnerability allows project administrators to use the Harbor API to create a robot account with unauthorized push and/or pull access permissions to a project they don't have access or control for. The Harbor API did not enforce the proper project permissions and project scope on the API request to create a new robot account.

CVSS3: 7.5
EPSS: Низкий
fstec логотип

BDU:2019-04536

почти 7 лет назад

Уязвимость реестра для Docker-контейнеров Harbor, связанная с ошибками использования стандартных разрешений, позволяющая нарушителю повысить свои привилегии и получить несанкционированный доступ к смежным проектам

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2019-16097

около 7 лет назад

core/api/user.go in Harbor 1.7.0 through 1.8.2 allows non-admin users to create admin accounts via the POST /api/users API, when Harbor is setup with DB as authentication backend and allow user to do self-registration. Fixed version: v1.7.6 v1.8.3. v.1.9.0. Workaround without applying the fix: configure Harbor to use non-DB authentication backend such as LDAP.

CVSS3: 6.5
EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
nvd логотип
CVE-2020-13788

Harbor prior to 2.0.1 allows SSRF with this limitation: an attacker with the ability to edit projects can scan ports of hosts accessible on the Harbor server's intranet.

CVSS3: 4.3
1%
Низкий
около 6 лет назад
nvd логотип
CVE-2019-19029

Cloud Native Computing Foundation Harbor prior to 1.8.6 and 1.9.3 allows SQL Injection via user-groups in the VMware Harbor Container Registry for the Pivotal Platform.

CVSS3: 7.2
2%
Низкий
больше 6 лет назад
nvd логотип
CVE-2019-19026

Cloud Native Computing Foundation Harbor prior to 1.8.6 and 1.9.3 allows SQL Injection via project quotas in the VMware Harbor Container Registry for the Pivotal Platform.

CVSS3: 4.9
1%
Низкий
больше 6 лет назад
nvd логотип
CVE-2019-19025

Cloud Native Computing Foundation Harbor prior to 1.8.6 and 1.9.3 allows CSRF in the VMware Harbor Container Registry for the Pivotal Platform.

CVSS3: 8.8
1%
Низкий
больше 6 лет назад
nvd логотип
CVE-2019-19023

Cloud Native Computing Foundation Harbor prior to 1.8.6 and 1.9.3 has a Privilege Escalation Vulnerability in the VMware Harbor Container Registry for the Pivotal Platform.

CVSS3: 8.8
2%
Низкий
больше 6 лет назад
fstec логотип
BDU:2021-02130

Уязвимость реестра для Docker-контейнеров Harbor, связанная с подделкой межсайтовых запросов, позволяющая нарушителю оказать воздействие на конфиденциальность, целостность и доступность защищаемой информации

CVSS3: 8.8
1%
Низкий
больше 6 лет назад
nvd логотип
CVE-2019-3990

A User Enumeration flaw exists in Harbor. The issue is present in the "/users" API endpoint. This endpoint is supposed to be restricted to administrators. This restriction is able to be bypassed and information can be obtained about registered users can be obtained via the "search" functionality.

CVSS3: 4.3
1%
Низкий
почти 7 лет назад
nvd логотип
CVE-2019-16919

Harbor API has a Broken Access Control vulnerability. The vulnerability allows project administrators to use the Harbor API to create a robot account with unauthorized push and/or pull access permissions to a project they don't have access or control for. The Harbor API did not enforce the proper project permissions and project scope on the API request to create a new robot account.

CVSS3: 7.5
2%
Низкий
почти 7 лет назад
fstec логотип
BDU:2019-04536

Уязвимость реестра для Docker-контейнеров Harbor, связанная с ошибками использования стандартных разрешений, позволяющая нарушителю повысить свои привилегии и получить несанкционированный доступ к смежным проектам

CVSS3: 7.5
2%
Низкий
почти 7 лет назад
nvd логотип
CVE-2019-16097

core/api/user.go in Harbor 1.7.0 through 1.8.2 allows non-admin users to create admin accounts via the POST /api/users API, when Harbor is setup with DB as authentication backend and allow user to do self-registration. Fixed version: v1.7.6 v1.8.3. v.1.9.0. Workaround without applying the fix: configure Harbor to use non-DB authentication backend such as LDAP.

CVSS3: 6.5
22%
Средний
около 7 лет назад

Уязвимостей на страницу


Поделиться