CVE-2022-31671
7.4
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L
Exploitability: 3.1 / Impact: 3.7
Source: NVD
Description
Harbor fails to validate user permissions when reading and updating job execution logs through the P2P preheat execution logs. By sending a request that attempts to read/update P2P preheat execution logs and specifying different job IDs, malicious authenticated users could read all the job logs stored in the Harbor database.
Affected (2)
Products: Linuxfoundation: Harbor
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| From 2.0.0 to 2.4.3 |
Related CWEs
CWE-285
Improper Authorization
The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.
CWE-863
Incorrect Authorization
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check. This allows attackers to bypass intended access restrictions.
References (2)
Source: security@vmware.com
Vendor Advisory
Source: security@vmware.com
Vendor Advisory
Timeline
No history available yet.