6.5

CVE-2019-16097

core/api/user.go in Harbor 1.7.0 through 1.8.2 allows non-admin users to create admin accounts via the POST /api/users API, when Harbor is setup with DB as authentication backend and allow user to do self-registration. Fixed version: v1.7.6 v1.8.3. v.1.9.0. Workaround without applying the fix: configure Harbor to use non-DB authentication backend such as LDAP.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
LinuxfoundationHarbor Version1.7.0 Update-
LinuxfoundationHarbor Version1.7.0 Updaterc1
LinuxfoundationHarbor Version1.7.0 Updaterc2
LinuxfoundationHarbor Version1.7.1
LinuxfoundationHarbor Version1.7.2
LinuxfoundationHarbor Version1.7.3
LinuxfoundationHarbor Version1.7.4
LinuxfoundationHarbor Version1.7.5
LinuxfoundationHarbor Version1.8.0 Update-
LinuxfoundationHarbor Version1.8.0 Updaterc1
LinuxfoundationHarbor Version1.8.0 Updaterc2
LinuxfoundationHarbor Version1.8.1
LinuxfoundationHarbor Version1.8.2 Update-
LinuxfoundationHarbor Version1.8.2 Updaterc1
LinuxfoundationHarbor Version1.8.2 Updaterc2
LinuxfoundationHarbor Version1.9.0 Updaterc1
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 93.7% 0.998
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 6.5 2.8 3.6
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
nvd@nist.gov 4 8 2.9
AV:N/AC:L/Au:S/C:N/I:P/A:N
CWE-862 Missing Authorization

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.