VYPR
Medium severity6.5NVD Advisory· Published Sep 8, 2019· Updated Jun 17, 2026

CVE-2019-16097

CVE-2019-16097

Description

core/api/user.go in Harbor 1.7.0 through 1.8.2 allows non-admin users to create admin accounts via the POST /api/users API, when Harbor is setup with DB as authentication backend and allow user to do self-registration. Fixed version: v1.7.6 v1.8.3. v.1.9.0. Workaround without applying the fix: configure Harbor to use non-DB authentication backend such as LDAP.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
github.com/goharbor/harborGo
>= 1.7.0, < 1.9.0-rc11.9.0-rc1

Affected products

18
  • Harbor/Harbordescription
  • ghsa-coords
    Range: >= 1.7.0, < 1.9.0-rc1
  • cpe:2.3:a:linuxfoundation:harbor:1.7.0:-:*:*:*:*:*:*+ 15 more
    • cpe:2.3:a:linuxfoundation:harbor:1.7.0:-:*:*:*:*:*:*
    • cpe:2.3:a:linuxfoundation:harbor:1.7.0:rc1:*:*:*:*:*:*
    • cpe:2.3:a:linuxfoundation:harbor:1.7.0:rc2:*:*:*:*:*:*
    • cpe:2.3:a:linuxfoundation:harbor:1.7.1:*:*:*:*:*:*:*
    • cpe:2.3:a:linuxfoundation:harbor:1.7.2:*:*:*:*:*:*:*
    • cpe:2.3:a:linuxfoundation:harbor:1.7.3:*:*:*:*:*:*:*
    • cpe:2.3:a:linuxfoundation:harbor:1.7.4:*:*:*:*:*:*:*
    • cpe:2.3:a:linuxfoundation:harbor:1.7.5:*:*:*:*:*:*:*
    • cpe:2.3:a:linuxfoundation:harbor:1.8.0:-:*:*:*:*:*:*
    • cpe:2.3:a:linuxfoundation:harbor:1.8.0:rc1:*:*:*:*:*:*
    • cpe:2.3:a:linuxfoundation:harbor:1.8.0:rc2:*:*:*:*:*:*
    • cpe:2.3:a:linuxfoundation:harbor:1.8.1:*:*:*:*:*:*:*
    • cpe:2.3:a:linuxfoundation:harbor:1.8.2:-:*:*:*:*:*:*
    • cpe:2.3:a:linuxfoundation:harbor:1.8.2:rc1:*:*:*:*:*:*
    • cpe:2.3:a:linuxfoundation:harbor:1.8.2:rc2:*:*:*:*:*:*
    • cpe:2.3:a:linuxfoundation:harbor:1.9.0:rc1:*:*:*:*:*:*

Patches

Vulnerability mechanics

References

9

News mentions

0

No linked articles in our index yet.