Harbor fails to validate the user permissions when updating tag retention policies. By sending a request to update a tag retention policy with an id that belongs to a project that the currently authenticated user doesn’t have access to, the attacker could modify tag retention policies configured in other projects.
oryginał ENCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:NLinuxfoundation Harbor
APPLinuxfoundation1.0.0 – 1.10.13 (bez)2.0.0 – 2.4.3 (bez)2.5.0 – 2.5.2 (bez)
Powiązane podatności
Hardkodowane dane uwierzytelniające w GoHarbor Harbor — nieautoryzowany dostęp do panelu
Harbor fails to validate user permissions while deleting Webhook policies, allowing malicious users to view, u...
Harbor fails to validate the user permissions when updating p2p preheat policies. By sending a request to upda...
Harbor fails to validate user permissions when reading and updating job execution logs through the P2P preheat...
An access control issue in Harbor v1.X.X to v2.5.3 allows attackers to access public and private image reposit...