CVE-2022-46463
- EPSS 72.53%
- Veröffentlicht 13.01.2023 00:15:09
- Zuletzt bearbeitet 08.04.2025 14:15:29
An access control issue in Harbor v1.X.X to v2.5.3 allows attackers to access public and private image repositories without authentication. NOTE: the vendor's position is that this "is clearly described in the documentation as a feature."
CVE-2019-19030
- EPSS 35.56%
- Veröffentlicht 26.12.2022 22:15:10
- Zuletzt bearbeitet 14.04.2025 17:15:22
Cloud Native Computing Foundation Harbor before 1.10.3 and 2.x before 2.0.1 allows resource enumeration because unauthenticated API calls reveal (via the HTTP status code) whether a resource exists.
CVE-2020-29662
- EPSS 0.36%
- Veröffentlicht 02.02.2021 21:15:13
- Zuletzt bearbeitet 21.11.2024 05:24:23
In Harbor 2.0 before 2.0.5 and 2.1.x before 2.1.2 the catalog’s registry API is exposed on an unauthenticated path.
CVE-2020-13794
- EPSS 0.31%
- Veröffentlicht 30.09.2020 18:15:21
- Zuletzt bearbeitet 21.11.2024 05:01:52
Harbor 1.9.* 1.10.* and 2.0.* allows Exposure of Sensitive Information to an Unauthorized Actor.
CVE-2020-13788
- EPSS 0.31%
- Veröffentlicht 15.07.2020 21:15:12
- Zuletzt bearbeitet 21.11.2024 05:01:51
Harbor prior to 2.0.1 allows SSRF with this limitation: an attacker with the ability to edit projects can scan ports of hosts accessible on the Harbor server's intranet.
CVE-2019-19029
- EPSS 0.77%
- Veröffentlicht 20.03.2020 03:15:13
- Zuletzt bearbeitet 21.11.2024 04:34:01
Cloud Native Computing Foundation Harbor prior to 1.8.6 and 1.9.3 allows SQL Injection via user-groups in the VMware Harbor Container Registry for the Pivotal Platform.
CVE-2019-19026
- EPSS 0.41%
- Veröffentlicht 20.03.2020 03:15:13
- Zuletzt bearbeitet 21.11.2024 04:34:01
Cloud Native Computing Foundation Harbor prior to 1.8.6 and 1.9.3 allows SQL Injection via project quotas in the VMware Harbor Container Registry for the Pivotal Platform.
CVE-2019-19025
- EPSS 0.38%
- Veröffentlicht 20.03.2020 03:15:13
- Zuletzt bearbeitet 21.11.2024 04:34:01
Cloud Native Computing Foundation Harbor prior to 1.8.6 and 1.9.3 allows CSRF in the VMware Harbor Container Registry for the Pivotal Platform.
CVE-2019-19023
- EPSS 0.41%
- Veröffentlicht 20.03.2020 03:15:13
- Zuletzt bearbeitet 21.11.2024 04:34:01
Cloud Native Computing Foundation Harbor prior to 1.8.6 and 1.9.3 has a Privilege Escalation Vulnerability in the VMware Harbor Container Registry for the Pivotal Platform.
CVE-2019-3990
- EPSS 0.31%
- Veröffentlicht 03.12.2019 17:15:11
- Zuletzt bearbeitet 21.11.2024 04:43:01
A User Enumeration flaw exists in Harbor. The issue is present in the "/users" API endpoint. This endpoint is supposed to be restricted to administrators. This restriction is able to be bypassed and information can be obtained about registered users ...