VYPR

Harbor

by Linux Foundation

Source repositories

CVEs (24)

  • CVE-2020-13788MedJul 15, 2020
    risk 0.28cvss 4.3epss 0.01

    Harbor prior to 2.0.1 allows SSRF with this limitation: an attacker with the ability to edit projects can scan ports of hosts accessible on the Harbor server's intranet.

  • CVE-2019-3990MedDec 3, 2019
    risk 0.28cvss 4.3epss 0.01

    A User Enumeration flaw exists in Harbor. The issue is present in the "/users" API endpoint. This endpoint is supposed to be restricted to administrators. This restriction is able to be bypassed and information can be obtained about registered users can be obtained via the…

  • CVE-2019-19026MedMar 20, 2020
    risk 0.25cvss 4.9epss 0.01

    Cloud Native Computing Foundation Harbor prior to 1.8.6 and 1.9.3 allows SQL Injection via project quotas in the VMware Harbor Container Registry for the Pivotal Platform.

  • CVE-2024-22261LowJun 11, 2024
    risk 0.18cvss 2.7epss 0.00

    SQL-Injection in Harbor allows priviledge users to leak the task IDs

Page 2 of 2