← Back

CVE-2022-31666

nvd nist
Published: Nov 14, 2024Modified: Jun 17, 2026

JSON object

Loading...
5.4
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Exploitability: 2.8 / Impact: 2.5
Source: NVD

Description

Harbor fails to validate user permissions while deleting Webhook policies, allowing malicious users to view, update and delete Webhook policies of other users.  The attacker could modify Webhook policies configured in other projects.

Affected (2)

Harbor
Configuration A
2 vulnerable
Vulnerable SoftwareAffected Versions
Linuxfoundation
From 2.0.0 to 2.4.3
From 2.5.0 to 2.5.2

References (1)

Timeline

No history available yet.