Логотип exploitDog
product: "harbor"
Консоль
Логотип exploitDog

exploitDog

product: "harbor"

Количество 80

Количество 80

nvd логотип

CVE-2023-20902

около 2 лет назад

A timing condition in Harbor 2.6.x and below, Harbor 2.7.2 and below,  Harbor 2.8.2 and below, and Harbor 1.10.17 and below allows an attacker with network access to create jobs/stop job tasks and retrieve job task information.

CVSS3: 5.9
EPSS: Низкий
nvd логотип

CVE-2022-46463

почти 3 года назад

An access control issue in Harbor v1.X.X to v2.5.3 allows attackers to access public and private image repositories without authentication. NOTE: the vendor's position is that this "is clearly described in the documentation as a feature."

CVSS3: 7.5
EPSS: Высокий
nvd логотип

CVE-2022-31671

около 1 года назад

Harbor fails to validate user permissions when reading and updating job execution logs through the P2P preheat execution logs. By sending a request that attempts to read/update P2P preheat execution logs and specifying different job IDs, malicious authenticated users could read all the job logs stored in the Harbor database.

CVSS3: 7.4
EPSS: Низкий
nvd логотип

CVE-2022-31670

около 1 года назад

Harbor fails to validate the user permissions when updating tag retention policies.  By sending a request to update a tag retention policy with an id that belongs to a project that the currently authenticated user doesn’t have access to, the attacker could modify tag retention policies configured in other projects.

CVSS3: 7.7
EPSS: Низкий
nvd логотип

CVE-2022-31669

около 1 года назад

Harbor fails to validate the user permissions when updating tag immutability policies.  By sending a request to update a tag immutability policy with an id that belongs to a project that the currently authenticated user doesn’t have access to, the attacker could modify tag immutability policies configured in other projects.

CVSS3: 6.4
EPSS: Низкий
nvd логотип

CVE-2022-31668

около 1 года назад

Harbor fails to validate the user permissions when updating p2p preheat policies. By sending a request to update a p2p preheat policy with an id that belongs to a project that the currently authenticated user doesn't have access to, the attacker could modify p2p preheat policies configured in other projects.

CVSS3: 7.4
EPSS: Низкий
nvd логотип

CVE-2022-31667

около 1 года назад

Harbor fails to validate the user permissions when updating a robot account that belongs to a project that the authenticated user doesn’t have access to.  By sending a request that attempts to update a robot account, and specifying a robot account id and robot account name that belongs to a different project that the user doesn’t have access to, it was possible to revoke the robot account permissions.

CVSS3: 6.4
EPSS: Низкий
nvd логотип

CVE-2022-31666

около 1 года назад

Harbor fails to validate user permissions while deleting Webhook policies, allowing malicious users to view, update and delete Webhook policies of other users.  The attacker could modify Webhook policies configured in other projects.

CVSS3: 7.7
EPSS: Низкий
nvd логотип

CVE-2020-29662

почти 5 лет назад

In Harbor 2.0 before 2.0.5 and 2.1.x before 2.1.2 the catalog’s registry API is exposed on an unauthenticated path.

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2020-13794

около 5 лет назад

Harbor 1.9.* 1.10.* and 2.0.* allows Exposure of Sensitive Information to an Unauthorized Actor.

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2020-13788

больше 5 лет назад

Harbor prior to 2.0.1 allows SSRF with this limitation: an attacker with the ability to edit projects can scan ports of hosts accessible on the Harbor server's intranet.

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2019-3990

около 6 лет назад

A User Enumeration flaw exists in Harbor. The issue is present in the "/users" API endpoint. This endpoint is supposed to be restricted to administrators. This restriction is able to be bypassed and information can be obtained about registered users can be obtained via the "search" functionality.

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2019-19030

почти 3 года назад

Cloud Native Computing Foundation Harbor before 1.10.3 and 2.x before 2.0.1 allows resource enumeration because unauthenticated API calls reveal (via the HTTP status code) whether a resource exists.

CVSS3: 5.3
EPSS: Средний
nvd логотип

CVE-2019-16097

больше 6 лет назад

core/api/user.go in Harbor 1.7.0 through 1.8.2 allows non-admin users to create admin accounts via the POST /api/users API, when Harbor is setup with DB as authentication backend and allow user to do self-registration. Fixed version: v1.7.6 v1.8.3. v.1.9.0. Workaround without applying the fix: configure Harbor to use non-DB authentication backend such as LDAP.

CVSS3: 6.5
EPSS: Критический
nvd логотип

CVE-2017-17697

около 8 лет назад

The Ping() function in ui/api/target.go in Harbor through 1.3.0-rc4 has SSRF via the endpoint parameter to /api/targets/ping.

CVSS3: 8.6
EPSS: Низкий
fstec логотип

BDU:2021-02130

почти 6 лет назад

Уязвимость реестра для Docker-контейнеров Harbor, связанная с подделкой межсайтовых запросов, позволяющая нарушителю оказать воздействие на конфиденциальность, целостность и доступность защищаемой информации

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-w4x5-jqq4-qc8x

больше 4 лет назад

SQL Injection in Cloud Native Computing Foundation Harbor

CVSS3: 4.9
EPSS: Низкий
github логотип

GHSA-rffr-c932-cpxv

больше 4 лет назад

Cross-site Request Forgery (CSRF) in Cloud Native Computing Foundation Harbor

CVSS3: 7.6
EPSS: Низкий
github логотип

GHSA-q6cj-6jvq-jwmh

больше 4 лет назад

Privilege Escalation in Cloud Native Computing Foundation Harbor

CVSS3: 9.3
EPSS: Низкий
github логотип

GHSA-jr34-mff8-pc6f

больше 4 лет назад

SQL Injection in Cloud Native Computing Foundation Harbor

CVSS3: 7.2
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2023-20902

A timing condition in Harbor 2.6.x and below, Harbor 2.7.2 and below,  Harbor 2.8.2 and below, and Harbor 1.10.17 and below allows an attacker with network access to create jobs/stop job tasks and retrieve job task information.

CVSS3: 5.9
0%
Низкий
около 2 лет назад
nvd логотип
CVE-2022-46463

An access control issue in Harbor v1.X.X to v2.5.3 allows attackers to access public and private image repositories without authentication. NOTE: the vendor's position is that this "is clearly described in the documentation as a feature."

CVSS3: 7.5
73%
Высокий
почти 3 года назад
nvd логотип
CVE-2022-31671

Harbor fails to validate user permissions when reading and updating job execution logs through the P2P preheat execution logs. By sending a request that attempts to read/update P2P preheat execution logs and specifying different job IDs, malicious authenticated users could read all the job logs stored in the Harbor database.

CVSS3: 7.4
0%
Низкий
около 1 года назад
nvd логотип
CVE-2022-31670

Harbor fails to validate the user permissions when updating tag retention policies.  By sending a request to update a tag retention policy with an id that belongs to a project that the currently authenticated user doesn’t have access to, the attacker could modify tag retention policies configured in other projects.

CVSS3: 7.7
0%
Низкий
около 1 года назад
nvd логотип
CVE-2022-31669

Harbor fails to validate the user permissions when updating tag immutability policies.  By sending a request to update a tag immutability policy with an id that belongs to a project that the currently authenticated user doesn’t have access to, the attacker could modify tag immutability policies configured in other projects.

CVSS3: 6.4
0%
Низкий
около 1 года назад
nvd логотип
CVE-2022-31668

Harbor fails to validate the user permissions when updating p2p preheat policies. By sending a request to update a p2p preheat policy with an id that belongs to a project that the currently authenticated user doesn't have access to, the attacker could modify p2p preheat policies configured in other projects.

CVSS3: 7.4
0%
Низкий
около 1 года назад
nvd логотип
CVE-2022-31667

Harbor fails to validate the user permissions when updating a robot account that belongs to a project that the authenticated user doesn’t have access to.  By sending a request that attempts to update a robot account, and specifying a robot account id and robot account name that belongs to a different project that the user doesn’t have access to, it was possible to revoke the robot account permissions.

CVSS3: 6.4
0%
Низкий
около 1 года назад
nvd логотип
CVE-2022-31666

Harbor fails to validate user permissions while deleting Webhook policies, allowing malicious users to view, update and delete Webhook policies of other users.  The attacker could modify Webhook policies configured in other projects.

CVSS3: 7.7
0%
Низкий
около 1 года назад
nvd логотип
CVE-2020-29662

In Harbor 2.0 before 2.0.5 and 2.1.x before 2.1.2 the catalog’s registry API is exposed on an unauthenticated path.

CVSS3: 5.3
0%
Низкий
почти 5 лет назад
nvd логотип
CVE-2020-13794

Harbor 1.9.* 1.10.* and 2.0.* allows Exposure of Sensitive Information to an Unauthorized Actor.

CVSS3: 4.3
0%
Низкий
около 5 лет назад
nvd логотип
CVE-2020-13788

Harbor prior to 2.0.1 allows SSRF with this limitation: an attacker with the ability to edit projects can scan ports of hosts accessible on the Harbor server's intranet.

CVSS3: 4.3
0%
Низкий
больше 5 лет назад
nvd логотип
CVE-2019-3990

A User Enumeration flaw exists in Harbor. The issue is present in the "/users" API endpoint. This endpoint is supposed to be restricted to administrators. This restriction is able to be bypassed and information can be obtained about registered users can be obtained via the "search" functionality.

CVSS3: 4.3
0%
Низкий
около 6 лет назад
nvd логотип
CVE-2019-19030

Cloud Native Computing Foundation Harbor before 1.10.3 and 2.x before 2.0.1 allows resource enumeration because unauthenticated API calls reveal (via the HTTP status code) whether a resource exists.

CVSS3: 5.3
36%
Средний
почти 3 года назад
nvd логотип
CVE-2019-16097

core/api/user.go in Harbor 1.7.0 through 1.8.2 allows non-admin users to create admin accounts via the POST /api/users API, when Harbor is setup with DB as authentication backend and allow user to do self-registration. Fixed version: v1.7.6 v1.8.3. v.1.9.0. Workaround without applying the fix: configure Harbor to use non-DB authentication backend such as LDAP.

CVSS3: 6.5
94%
Критический
больше 6 лет назад
nvd логотип
CVE-2017-17697

The Ping() function in ui/api/target.go in Harbor through 1.3.0-rc4 has SSRF via the endpoint parameter to /api/targets/ping.

CVSS3: 8.6
0%
Низкий
около 8 лет назад
fstec логотип
BDU:2021-02130

Уязвимость реестра для Docker-контейнеров Harbor, связанная с подделкой межсайтовых запросов, позволяющая нарушителю оказать воздействие на конфиденциальность, целостность и доступность защищаемой информации

CVSS3: 8.8
0%
Низкий
почти 6 лет назад
github логотип
GHSA-w4x5-jqq4-qc8x

SQL Injection in Cloud Native Computing Foundation Harbor

CVSS3: 4.9
0%
Низкий
больше 4 лет назад
github логотип
GHSA-rffr-c932-cpxv

Cross-site Request Forgery (CSRF) in Cloud Native Computing Foundation Harbor

CVSS3: 7.6
0%
Низкий
больше 4 лет назад
github логотип
GHSA-q6cj-6jvq-jwmh

Privilege Escalation in Cloud Native Computing Foundation Harbor

CVSS3: 9.3
0%
Низкий
больше 4 лет назад
github логотип
GHSA-jr34-mff8-pc6f

SQL Injection in Cloud Native Computing Foundation Harbor

CVSS3: 7.2
0%
Низкий
больше 4 лет назад

Уязвимостей на страницу