Логотип exploitDog
bind:CVE-2019-16097
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2019-16097

Количество 2

Количество 2

nvd логотип

CVE-2019-16097

почти 6 лет назад

core/api/user.go in Harbor 1.7.0 through 1.8.2 allows non-admin users to create admin accounts via the POST /api/users API, when Harbor is setup with DB as authentication backend and allow user to do self-registration. Fixed version: v1.7.6 v1.8.3. v.1.9.0. Workaround without applying the fix: configure Harbor to use non-DB authentication backend such as LDAP.

CVSS3: 6.5
EPSS: Критический
github логотип

GHSA-9wvh-ff5f-xjpj

больше 3 лет назад

Missing Authorization in Harbor

CVSS3: 6.5
EPSS: Критический

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2019-16097

core/api/user.go in Harbor 1.7.0 through 1.8.2 allows non-admin users to create admin accounts via the POST /api/users API, when Harbor is setup with DB as authentication backend and allow user to do self-registration. Fixed version: v1.7.6 v1.8.3. v.1.9.0. Workaround without applying the fix: configure Harbor to use non-DB authentication backend such as LDAP.

CVSS3: 6.5
93%
Критический
почти 6 лет назад
github логотип
GHSA-9wvh-ff5f-xjpj

Missing Authorization in Harbor

CVSS3: 6.5
93%
Критический
больше 3 лет назад

Уязвимостей на страницу