VYPR
High severity7.5NVD Advisory· Published Oct 18, 2019· Updated Jun 17, 2026

CVE-2019-16919

CVE-2019-16919

Description

Harbor API has a Broken Access Control vulnerability. The vulnerability allows project administrators to use the Harbor API to create a robot account with unauthorized push and/or pull access permissions to a project they don't have access or control for. The Harbor API did not enforce the proper project permissions and project scope on the API request to create a new robot account.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

6
  • Harbor/Harborllm-fuzzy
  • Harbor/Harbor APIdescription
  • cpe:2.3:a:linuxfoundation:harbor:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:linuxfoundation:harbor:*:*:*:*:*:*:*:*range: >=1.8.0,<=1.8.3
    • cpe:2.3:a:linuxfoundation:harbor:1.9.0:*:*:*:*:*:*:*
  • cpe:2.3:a:vmware:cloud_foundation:-:*:*:*:*:*:*:*
  • cpe:2.3:a:vmware:harbor_container_registry:*:*:*:*:*:pivotal_cloud_foundry:*:*
    Range: >=1.7.0,<=1.7.6

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.