Linuxfoundation

Harbor

24 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.37%
  • Veröffentlicht 09.11.2023 01:15:07
  • Zuletzt bearbeitet 21.11.2024 07:41:47

A timing condition in Harbor 2.6.x and below, Harbor 2.7.2 and below,  Harbor 2.8.2 and below, and Harbor 1.10.17 and below allows an attacker with network access to create jobs/stop job tasks and retrieve job task information.

  • EPSS 6.24%
  • Veröffentlicht 13.01.2023 00:15:09
  • Zuletzt bearbeitet 08.04.2025 14:15:29

An access control issue in Harbor v1.X.X to v2.5.3 allows attackers to access public and private image repositories without authentication. NOTE: the vendor's position is that this "is clearly described in the documentation as a feature."

Exploit
  • EPSS 1.89%
  • Veröffentlicht 26.12.2022 22:15:10
  • Zuletzt bearbeitet 14.04.2025 17:15:22

Cloud Native Computing Foundation Harbor before 1.10.3 and 2.x before 2.0.1 allows resource enumeration because unauthenticated API calls reveal (via the HTTP status code) whether a resource exists.

  • EPSS 0.72%
  • Veröffentlicht 02.02.2021 21:15:13
  • Zuletzt bearbeitet 21.11.2024 05:24:23

In Harbor 2.0 before 2.0.5 and 2.1.x before 2.1.2 the catalog’s registry API is exposed on an unauthenticated path.

Exploit
  • EPSS 1.27%
  • Veröffentlicht 30.09.2020 18:15:21
  • Zuletzt bearbeitet 21.11.2024 05:01:52

Harbor 1.9.* 1.10.* and 2.0.* allows Exposure of Sensitive Information to an Unauthorized Actor.

Exploit
  • EPSS 1.28%
  • Veröffentlicht 15.07.2020 21:15:12
  • Zuletzt bearbeitet 21.11.2024 05:01:51

Harbor prior to 2.0.1 allows SSRF with this limitation: an attacker with the ability to edit projects can scan ports of hosts accessible on the Harbor server's intranet.

  • EPSS 2.1%
  • Veröffentlicht 20.03.2020 03:15:13
  • Zuletzt bearbeitet 21.11.2024 04:34:01

Cloud Native Computing Foundation Harbor prior to 1.8.6 and 1.9.3 allows SQL Injection via user-groups in the VMware Harbor Container Registry for the Pivotal Platform.

  • EPSS 1.42%
  • Veröffentlicht 20.03.2020 03:15:13
  • Zuletzt bearbeitet 21.11.2024 04:34:01

Cloud Native Computing Foundation Harbor prior to 1.8.6 and 1.9.3 allows SQL Injection via project quotas in the VMware Harbor Container Registry for the Pivotal Platform.

  • EPSS 1.02%
  • Veröffentlicht 20.03.2020 03:15:13
  • Zuletzt bearbeitet 21.11.2024 04:34:01

Cloud Native Computing Foundation Harbor prior to 1.8.6 and 1.9.3 allows CSRF in the VMware Harbor Container Registry for the Pivotal Platform.

  • EPSS 1.62%
  • Veröffentlicht 20.03.2020 03:15:13
  • Zuletzt bearbeitet 21.11.2024 04:34:01

Cloud Native Computing Foundation Harbor prior to 1.8.6 and 1.9.3 has a Privilege Escalation Vulnerability in the VMware Harbor Container Registry for the Pivotal Platform.