Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2019-3990


A User Enumeration flaw exists in Harbor. The issue is present in the "/users" API endpoint. This endpoint is supposed to be restricted to administrators. This restriction is able to be bypassed and information can be obtained about registered users can be obtained via the "search" functionality.


Published

2019-12-03T17:15:11.727

Last Modified

2024-11-21T04:43:01.013

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 4.3 (MEDIUM)

CVSSv2 Vector

AV:N/AC:L/Au:S/C:P/I:N/A:N

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: SINGLE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: NONE
  • Availability Impact: NONE
Exploitability Score

8.0

Impact Score

2.9

Weaknesses
  • Type: Primary
    CWE-269

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application linuxfoundation harbor ≤ 1.7.6 Yes
Application linuxfoundation harbor ≤ 1.8.5 Yes
Application linuxfoundation harbor 1.9.0 Yes
Application linuxfoundation harbor 1.9.0 Yes
Application linuxfoundation harbor 1.9.0 Yes
Application linuxfoundation harbor 1.9.1 Yes
Application linuxfoundation harbor 1.9.1 Yes

References