<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Harbor</title>
  <link>https://cvedaily.com/pages/tags/harbor.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/harbor.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Harbor</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:58 +0000</lastBuildDate>
  <item>
    <title>[Critical] CVE-2026-4404 – Use of hard coded credentials in GoHarbor Harbor version 2.15.0 and below, allow...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-4404</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-4404</guid>
    <pubDate>Mon, 23 Mar 2026 15:16:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-4404</strong></p>
  <p>Use of hard coded credentials in GoHarbor Harbor version 2.15.0 and below, allows attackers to use the default password and gain access to the web UI.</p>
  <p><strong>CVSS:</strong> 9.4 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-4404">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-30086 – CNCF Harbor 2.13.x before 2.13.1 and 2.12.x before 2.12.4 allows information dis...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-30086</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-30086</guid>
    <pubDate>Fri, 25 Jul 2025 15:15:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-30086</strong></p>
  <p>CNCF Harbor 2.13.x before 2.13.1 and 2.12.x before 2.12.4 allows information disclosure by administrators who can exploit an ORM Leak present in the /api/v2.0/users endpoint to leak users' password hash and salt values. The q URL parameter allows a user to filter users by any column, and filter password=~ could be abused to leak out a user's password hash character by character. An attacker with…</p>
  <p><strong>CVSS:</strong> 4.9 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-30086">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-32019 – Harbor is an open source trusted cloud native registry project that stores, sign...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-32019</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-32019</guid>
    <pubDate>Wed, 23 Jul 2025 21:15:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-32019</strong></p>
  <p>Harbor is an open source trusted cloud native registry project that stores, signs, and scans content. Versions 2.11.2 and below, as well as versions 2.12.0-rc1 and 2.13.0-rc1, contain a vulnerability where the markdown field in the info tab page can be exploited to inject XSS code. This is fixed in versions 2.11.3 and 2.12.3.</p>
  <p><strong>CVSS:</strong> 4.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-32019">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2024-9773 – An issue was discovered in GitLab EE affecting all versions starting from 14.9 b...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-9773</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-9773</guid>
    <pubDate>Thu, 27 Mar 2025 13:15:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2024-9773</strong></p>
  <p>An issue was discovered in GitLab EE affecting all versions starting from 14.9 before 17.8.6, all versions starting from 17.9 before 17.8.3, all versions starting from 17.10 before 17.10.1. An input validation issue in the Harbor registry integration could have allowed a maintainer to add malicious code to the CLI commands shown in the UI.</p>
  <p><strong>CVSS:</strong> 3.7 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-9773">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-8647 – An issue was discovered in GitLab affecting all versions starting 15.2 to 17.4.6...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-8647</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-8647</guid>
    <pubDate>Thu, 12 Dec 2024 12:15:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-8647</strong></p>
  <p>An issue was discovered in GitLab affecting all versions starting 15.2 to 17.4.6, 17.5 prior to 17.5.4, and 17.6 prior to 17.6.2. On self hosted installs, it was possible to leak the anti-CSRF-token to an external site while the Harbor integration was enabled.</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-8647">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-8177 – An issue was discovered in GitLab CE/EE affecting all versions starting from 15...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-8177</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-8177</guid>
    <pubDate>Tue, 26 Nov 2024 19:15:31 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-8177</strong></p>
  <p>An issue was discovered in GitLab CE/EE affecting all versions starting from 15.6 prior to 17.4.5, starting from 17.5 prior to 17.5.3, starting from 17.6 prior to 17.6.1 which could cause Denial of Service via integrating a malicious harbor registry.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-407</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-8177">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-31671 – Harbor fails to validate user permissions when reading and updating job executio...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-31671</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-31671</guid>
    <pubDate>Thu, 14 Nov 2024 12:15:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-31671</strong></p>
  <p>Harbor fails to validate user permissions when reading and updating job execution logs through the P2P preheat execution logs. By sending a request that attempts to read/update P2P preheat execution logs and specifying different job IDs, malicious authenticated users could read all the job logs stored in the Harbor database.</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-285</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-31671">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-31670 – Harbor fails to validate the user permissions when updating tag retention polici...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-31670</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-31670</guid>
    <pubDate>Thu, 14 Nov 2024 12:15:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-31670</strong></p>
  <p>Harbor fails to validate the user permissions when updating tag retention policies.   By sending a request to update a tag retention policy with an id that belongs to a project that the currently authenticated user doesn’t have access to, the attacker could modify tag retention policies configured in other projects.</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-285</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-31670">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-31669 – Harbor fails to validate the user permissions when updating tag immutability pol...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-31669</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-31669</guid>
    <pubDate>Thu, 14 Nov 2024 12:15:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-31669</strong></p>
  <p>Harbor fails to validate the user permissions when updating tag immutability policies.   By sending a request to update a tag immutability policy with an id that belongs to a project that the currently authenticated user doesn’t have access to, the attacker could modify tag immutability policies configured in other projects.</p>
  <p><strong>CVSS:</strong> 6.4 · <strong>CWE:</strong> CWE-285</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-31669">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-31668 – Harbor fails to validate the user permissions when updating p2p preheat policies...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-31668</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-31668</guid>
    <pubDate>Thu, 14 Nov 2024 12:15:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-31668</strong></p>
  <p>Harbor fails to validate the user permissions when updating p2p preheat policies. By sending a request to update a p2p preheat policy with an id that belongs to a project that the currently authenticated user doesn't have access to, the attacker could modify p2p preheat policies configured in other projects.</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-285</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-31668">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-31667 – Harbor fails to validate the user permissions when updating a robot account that...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-31667</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-31667</guid>
    <pubDate>Thu, 14 Nov 2024 12:15:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-31667</strong></p>
  <p>Harbor fails to validate the user permissions when updating a robot account that belongs to a project that the authenticated user doesn’t have access to.   By sending a request that attempts to update a robot account, and specifying a robot account id and robot account name that belongs to a different project that the user doesn’t have access to, it was possible to revoke the robot account permis…</p>
  <p><strong>CVSS:</strong> 6.4 · <strong>CWE:</strong> CWE-285</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-31667">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-31666 – Harbor fails to validate user permissions while deleting Webhook policies, allow...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-31666</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-31666</guid>
    <pubDate>Thu, 14 Nov 2024 12:15:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-31666</strong></p>
  <p>Harbor fails to validate user permissions while deleting Webhook policies, allowing malicious users to view, update and delete Webhook policies of other users.  The attacker could modify Webhook policies configured in other projects.</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-285</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-31666">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-51419 – Cross Site Scripting vulnerability in Shenzhen Interconnection Harbor Network Te...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-51419</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-51419</guid>
    <pubDate>Wed, 30 Oct 2024 21:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-51419</strong></p>
  <p>Cross Site Scripting vulnerability in Shenzhen Interconnection Harbor Network Technology Co., Ltd Ofweek Online Exhibition v.1.0.0 allows a remote attacker to execute arbitrary code.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-51419">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-22278 – Incorrect user permission validation in Harbor &lt;v2.9.5 and Harbor &lt;v2.10.3 allow...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-22278</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-22278</guid>
    <pubDate>Fri, 02 Aug 2024 01:15:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-22278</strong></p>
  <p>Incorrect user permission validation in Harbor <v2.9.5 and Harbor <v2.10.3 allows authenticated users to modify configurations.</p>
  <p><strong>CVSS:</strong> 6.4 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-22278">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2024-22261 – SQL-Injection in Harbor allows priviledge users to leak the task IDs</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-22261</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-22261</guid>
    <pubDate>Tue, 11 Jun 2024 00:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2024-22261</strong></p>
  <p>SQL-Injection in Harbor allows priviledge users to leak the task IDs</p>
  <p><strong>CVSS:</strong> 2.7 · <strong>CWE:</strong> CWE-566</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-22261">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-22244 – Open Redirect in Harbor  &lt;=v2.8.4, &lt;=v2.9.2, and &lt;=v2.10.0 may redirect a user t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-22244</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-22244</guid>
    <pubDate>Mon, 10 Jun 2024 23:15:49 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-22244</strong></p>
  <p>Open Redirect in Harbor  <=v2.8.4, <=v2.9.2, and <=v2.10.0 may redirect a user to a malicious site.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-601</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-22244">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-20902 – A timing condition in Harbor 2.6.x and below, Harbor 2.7.2 and below,  Harbor 2...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-20902</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-20902</guid>
    <pubDate>Thu, 09 Nov 2023 01:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-20902</strong></p>
  <p>A timing condition in Harbor 2.6.x and below, Harbor 2.7.2 and below,  Harbor 2.8.2 and below, and Harbor 1.10.17 and below allows an attacker with network access to  create jobs/stop job tasks and retrieve job task information.</p>
  <p><strong>CVSS:</strong> 5.9 · <strong>CWE:</strong> CWE-362</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-20902">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-0632 – An issue has been discovered in GitLab affecting all versions starting from 15.2...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-0632</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-0632</guid>
    <pubDate>Wed, 02 Aug 2023 00:15:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-0632</strong></p>
  <p>An issue has been discovered in GitLab affecting all versions starting from 15.2 before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. A Regular Expression Denial of Service was possible by using crafted payloads to search Harbor Registry.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-1333</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-0632">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-46463 – An access control issue in Harbor v1.X.X to v2.5.3 allows attackers to access pu...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-46463</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-46463</guid>
    <pubDate>Fri, 13 Jan 2023 00:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-46463</strong></p>
  <p>An access control issue in Harbor v1.X.X to v2.5.3 allows attackers to access public and private image repositories without authentication. NOTE: the vendor's position is that this "is clearly described in the documentation as a feature."</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-306</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-46463">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2019-19030 – Cloud Native Computing Foundation Harbor before 1.10.3 and 2.x before 2.0.1 allo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-19030</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-19030</guid>
    <pubDate>Mon, 26 Dec 2022 22:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2019-19030</strong></p>
  <p>Cloud Native Computing Foundation Harbor before 1.10.3 and 2.x before 2.0.1 allows resource enumeration because unauthenticated API calls reveal (via the HTTP status code) whether a resource exists.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-204</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-19030">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2020-29662 – In Harbor 2.0 before 2.0.5 and 2.1.x before 2.1.2 the catalog’s registry API is ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-29662</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-29662</guid>
    <pubDate>Tue, 02 Feb 2021 21:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2020-29662</strong></p>
  <p>In Harbor 2.0 before 2.0.5 and 2.1.x before 2.1.2 the catalog’s registry API is exposed on an unauthenticated path.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-319</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-29662">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2020-13794 – Harbor 1.9.* 1.10.* and 2.0.* allows Exposure of Sensitive Information to an Una...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-13794</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-13794</guid>
    <pubDate>Wed, 30 Sep 2020 18:15:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2020-13794</strong></p>
  <p>Harbor 1.9.* 1.10.* and 2.0.* allows Exposure of Sensitive Information to an Unauthorized Actor.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-13794">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2020-13788 – Harbor prior to 2.0.1 allows SSRF with this limitation: an attacker with the abi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-13788</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-13788</guid>
    <pubDate>Wed, 15 Jul 2020 21:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2020-13788</strong></p>
  <p>Harbor prior to 2.0.1 allows SSRF with this limitation: an attacker with the ability to edit projects can scan ports of hosts accessible on the Harbor server's intranet.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-13788">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-19029 – Cloud Native Computing Foundation Harbor prior to 1.8.6 and 1.9.3 allows SQL Inj...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-19029</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-19029</guid>
    <pubDate>Fri, 20 Mar 2020 03:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-19029</strong></p>
  <p>Cloud Native Computing Foundation Harbor prior to 1.8.6 and 1.9.3 allows SQL Injection via user-groups in the VMware Harbor Container Registry for the Pivotal Platform.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-19029">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2019-19026 – Cloud Native Computing Foundation Harbor prior to 1.8.6 and 1.9.3 allows SQL Inj...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-19026</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-19026</guid>
    <pubDate>Fri, 20 Mar 2020 03:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2019-19026</strong></p>
  <p>Cloud Native Computing Foundation Harbor prior to 1.8.6 and 1.9.3 allows SQL Injection via project quotas in the VMware Harbor Container Registry for the Pivotal Platform.</p>
  <p><strong>CVSS:</strong> 4.9 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-19026">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-19025 – Cloud Native Computing Foundation Harbor prior to 1.8.6 and 1.9.3 allows CSRF in...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-19025</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-19025</guid>
    <pubDate>Fri, 20 Mar 2020 03:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-19025</strong></p>
  <p>Cloud Native Computing Foundation Harbor prior to 1.8.6 and 1.9.3 allows CSRF in the VMware Harbor Container Registry for the Pivotal Platform.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-19025">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-19023 – Cloud Native Computing Foundation Harbor prior to 1.8.6 and 1.9.3 has a Privileg...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-19023</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-19023</guid>
    <pubDate>Fri, 20 Mar 2020 03:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-19023</strong></p>
  <p>Cloud Native Computing Foundation Harbor prior to 1.8.6 and 1.9.3 has a Privilege Escalation Vulnerability in the VMware Harbor Container Registry for the Pivotal Platform.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-19023">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2019-3990 – A User Enumeration flaw exists in Harbor. The issue is present in the "/users" A...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-3990</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-3990</guid>
    <pubDate>Tue, 03 Dec 2019 17:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2019-3990</strong></p>
  <p>A User Enumeration flaw exists in Harbor. The issue is present in the "/users" API endpoint. This endpoint is supposed to be restricted to administrators. This restriction is able to be bypassed and information can be obtained about registered users can be obtained via the "search" functionality.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-3990">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-16919 – Harbor API has a Broken Access Control vulnerability. The vulnerability allows p...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-16919</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-16919</guid>
    <pubDate>Fri, 18 Oct 2019 12:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-16919</strong></p>
  <p>Harbor API has a Broken Access Control vulnerability. The vulnerability allows project administrators to use the Harbor API to create a robot account with unauthorized push and/or pull access permissions to a project they don't have access or control for. The Harbor API did not enforce the proper project permissions and project scope on the API request to create a new robot account.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-276</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-16919">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2019-16097 – core/api/user.go in Harbor 1.7.0 through 1.8.2 allows non-admin users to create ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-16097</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-16097</guid>
    <pubDate>Sun, 08 Sep 2019 16:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2019-16097</strong></p>
  <p>core/api/user.go in Harbor 1.7.0 through 1.8.2 allows non-admin users to create admin accounts via the POST /api/users API, when Harbor is setup with DB as authentication backend and allow user to do self-registration. Fixed version: v1.7.6 v1.8.3. v.1.9.0. Workaround without applying the fix: configure Harbor to use non-DB authentication backend such as LDAP.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-16097">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-17697 – The Ping() function in ui/api/target.go in Harbor through 1.3.0-rc4 has SSRF via...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-17697</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-17697</guid>
    <pubDate>Fri, 15 Dec 2017 09:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-17697</strong></p>
  <p>The Ping() function in ui/api/target.go in Harbor through 1.3.0-rc4 has SSRF via the endpoint parameter to /api/targets/ping.</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-17697">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
