CVE-2022-31671

HIGH

Harbor 2.0.0-2.4.2 and 1.0.0-1.10.12 - Authenticated Improper Authorization via P2P Preheat Execution Logs

Title source: llm
STIX 2.1

Description

Harbor fails to validate user permissions when reading and updating job execution logs through the P2P preheat execution logs. By sending a request that attempts to read/update P2P preheat execution logs and specifying different job IDs, malicious authenticated users could read all the job logs stored in the Harbor database.

Scores

CVSS v3 7.4
EPSS 0.0014
EPSS Percentile 33.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-285 CWE-863
Status published
Products (2)
goharbor/harbor 1.0.0 - 1.10.13Go
linuxfoundation/harbor 2.0.0 - 2.4.3
Published Nov 14, 2024
Tracked Since Feb 18, 2026