Harbor API has a Broken Access Control vulnerability. The vulnerability allows project administrators to use the Harbor API to create a robot account with unauthorized push and/or pull access permissions to a project they don't have access or control for. The Harbor API did not enforce the proper project permissions and project scope on the API request to create a new robot account.
2019-10-18T12:15:10.190
2024-11-21T04:31:20.477
Modified
CVSSv3.1: 7.5 (HIGH)
AV:N/AC:L/Au:N/C:N/I:P/A:N
10.0
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | linuxfoundation | harbor | ≤ 1.8.3 | Yes |
Application | linuxfoundation | harbor | 1.9.0 | Yes |
Application | vmware | cloud_foundation | - | Yes |
Application | vmware | harbor_container_registry | ≤ 1.7.6 | Yes |
Application | vmware | harbor_container_registry | < 1.8.4 | Yes |