BIT-harbor-2022-31671

See a problem?
Import Source
https://github.com/bitnami/vulndb/tree/main/data/harbor/BIT-harbor-2022-31671.json
JSON Data
https://api.test.osv.dev/v1/vulns/BIT-harbor-2022-31671
Aliases
Published
2024-11-20T07:10:37.789Z
Modified
2025-05-20T10:02:07.006Z
Summary
Harbor fails to validate the user permissions when reading and updating job execution logs through the P2P preheat execution logs
Details

Harbor fails to validate user permissions when reading and updating job execution logs through the P2P preheat execution logs. By sending a request that attempts to read/update P2P preheat execution logs and specifying different job IDs, malicious authenticated users could read all the job logs stored in the Harbor database.

Database specific
{
    "cpes": [
        "cpe:2.3:a:linuxfoundation:harbor:*:*:*:*:*:*:*:*"
    ],
    "severity": "High"
}
References

Affected packages

Bitnami / harbor

Package

Name
harbor
Purl
pkg:bitnami/harbor

Severity

  • 7.4 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L CVSS Calculator

Affected ranges

Type
SEMVER
Events
Introduced
2.0.0
Fixed
2.4.3
Introduced
2.5.0
Fixed
2.5.2