A timing condition in Harbor 2.6.x and below, Harbor 2.7.2 and below, Harbor 2.8.2 and below, and Harbor 1.10.17 and below allows an attacker with network access to create jobs/stop job tasks and retrieve job task information.
2023-11-09T01:15:07.660
2024-11-21T07:41:47.283
Modified
CVSSv3.1: 5.9 (MEDIUM)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | linuxfoundation | harbor | < 1.10.17 | Yes |
Application | linuxfoundation | harbor | ≤ 2.6.4 | Yes |
Application | linuxfoundation | harbor | < 2.7.3 | Yes |
Application | linuxfoundation | harbor | < 2.8.3 | Yes |