Harbor
Source repositories
CVEs (24)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2020-13788 | Med | 0.28 | 4.3 | 0.01 | Jul 15, 2020 | Harbor prior to 2.0.1 allows SSRF with this limitation: an attacker with the ability to edit projects can scan ports of hosts accessible on the Harbor server's intranet. | ||
| CVE-2019-3990 | Med | 0.28 | 4.3 | 0.01 | Dec 3, 2019 | A User Enumeration flaw exists in Harbor. The issue is present in the "/users" API endpoint. This endpoint is supposed to be restricted to administrators. This restriction is able to be bypassed and information can be obtained about registered users can be obtained via the… | ||
| CVE-2019-19026 | Med | 0.25 | 4.9 | 0.01 | Mar 20, 2020 | Cloud Native Computing Foundation Harbor prior to 1.8.6 and 1.9.3 allows SQL Injection via project quotas in the VMware Harbor Container Registry for the Pivotal Platform. | ||
| CVE-2024-22261 | Low | 0.18 | 2.7 | 0.00 | Jun 11, 2024 | SQL-Injection in Harbor allows priviledge users to leak the task IDs |
- risk 0.28cvss 4.3epss 0.01
Harbor prior to 2.0.1 allows SSRF with this limitation: an attacker with the ability to edit projects can scan ports of hosts accessible on the Harbor server's intranet.
- risk 0.28cvss 4.3epss 0.01
A User Enumeration flaw exists in Harbor. The issue is present in the "/users" API endpoint. This endpoint is supposed to be restricted to administrators. This restriction is able to be bypassed and information can be obtained about registered users can be obtained via the…
- risk 0.25cvss 4.9epss 0.01
Cloud Native Computing Foundation Harbor prior to 1.8.6 and 1.9.3 allows SQL Injection via project quotas in the VMware Harbor Container Registry for the Pivotal Platform.
- risk 0.18cvss 2.7epss 0.00
SQL-Injection in Harbor allows priviledge users to leak the task IDs
Page 2 of 2