CVE-2019-19026

MEDIUM

Cloud Native Computing Foundation Harbor <1.8.6,1.9.3 - SQL Injection

Title source: llm
STIX 2.1

Description

Cloud Native Computing Foundation Harbor prior to 1.8.6 and 1.9.3 allows SQL Injection via project quotas in the VMware Harbor Container Registry for the Pivotal Platform.

References (3)

Core 3
Core References
Third Party Advisory x_refsource_misc
https://github.com/goharbor/harbor/security/advisories
Third Party Advisory x_refsource_confirm
https://tanzu.vmware.com/security/cve-2019-19026

Scores

CVSS v3 4.9
EPSS 0.0034
EPSS Percentile 56.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-89
Status published
Products (3)
goharbor/harbor 1.7.0 - 1.8.6Go
linuxfoundation/harbor 1.7.0 - 1.8.6
pivotal/vmware_harbor_registry
Published Mar 20, 2020
Tracked Since Feb 18, 2026