BIT-harbor-2025-32019

See a problem?
Import Source
https://github.com/bitnami/vulndb/tree/main/data/harbor/BIT-harbor-2025-32019.json
JSON Data
https://api.test.osv.dev/v1/vulns/BIT-harbor-2025-32019
Aliases
Published
2025-07-29T05:40:29.320Z
Modified
2025-07-29T19:44:46.456966Z
Summary
Harbor's repository description page allows for XSS
Details

Harbor is an open source trusted cloud native registry project that stores, signs, and scans content. Versions 2.11.2 and below, as well as versions 2.12.0-rc1 and 2.13.0-rc1, contain a vulnerability where the markdown field in the info tab page can be exploited to inject XSS code. This is fixed in versions 2.11.3 and 2.12.3.

Database specific
{
    "severity": "Medium",
    "cpes": [
        "cpe:2.3:a:linuxfoundation:harbor:*:*:*:*:*:go:*:*"
    ]
}
References

Affected packages

Bitnami / harbor

Package

Name
harbor
Purl
pkg:bitnami/harbor

Severity

  • 4.1 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:N/A:N CVSS Calculator

Affected ranges

Type
SEMVER
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.4.0-rc1.0.20250421072404-a13a16383a41
Introduced
2.4.0-rc1.1
Fixed
2.11.3
Introduced
2.12.0-rc1
Fixed
2.12.4-rc1
Introduced
2.13.0-rc1
Fixed
2.13.1-rc1