CVE-2020-13794
Description
Harbor 1.9.* 1.10.* and 2.0.* allows Exposure of Sensitive Information to an Unauthorized Actor.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Harbor 1.9.x, 1.10.x, and 2.0.x expose sensitive information to unauthorized actors, allowing access to confidential data.
Vulnerability
Overview
According to the NVD entry [4], Harbor versions 1.9.*, 1.10.*, and 2.0.* allow Exposure of Sensitive Information to an Unauthorized Actor. The root cause is insufficient authorization checks on certain API endpoints that return sensitive data without proper authentication.
Exploitation
An attacker can exploit this vulnerability by sending crafted requests to affected Harbor instances without needing any prior authentication. The attack surface is network-based, requiring only access to the Harbor service.
Impact
Successful exploitation leads to disclosure of sensitive information such as configuration details, credentials, or other internal data, which could be leveraged for further attacks or unauthorized access.
Mitigation
Harbor has released version 2.0.3 which addresses this vulnerability [3]. Users are advised to upgrade to 2.0.3 or later. No workarounds are documented.
AI Insight generated on May 21, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
github.com/goharbor/harborGo | < 2.0.3 | 2.0.3 |
Affected products
3- Harbor/Harbordescription
- osv-coords2 versions
>= 1.9.0, < 2.0.3+ 1 more
- (no CPE)range: >= 1.9.0, < 2.0.3
- (no CPE)range: < 2.0.3
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
7- github.com/advisories/GHSA-q9p8-33wc-h432ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2020-13794ghsaADVISORY
- github.com/goharbor/harbor/releases/tag/v2.0.3ghsaWEB
- github.com/goharbor/harbor/releases/tag/v2.1.0ghsaWEB
- github.com/goharbor/harbor/security/advisories/GHSA-q9p8-33wc-h432ghsax_refsource_MISCWEB
- www.cybereagle.io/blog/cve-2020-13794ghsaWEB
- www.cybereagle.io/blog/cve-2020-13794/mitrex_refsource_MISC
News mentions
0No linked articles in our index yet.