Cloud Native Computing Foundation Harbor before 1.10.3 and 2.x before 2.0.1 allows resource enumeration because unauthenticated API calls reveal (via the HTTP status code) whether a resource exists.
2022-12-26T22:15:10.247
2025-04-14T17:15:22.360
Modified
CVSSv3.1: 5.3 (MEDIUM)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | linuxfoundation | harbor | < 1.10.3 | Yes |
Application | linuxfoundation | harbor | < 2.0.1 | Yes |