Linux / Harbor
24 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-4404 | Use of hard coded credentials in GoHarbor Harbor | CRITICAL | 9.4 | Mar 23, 2026 |
| CVE-2022-31668 | User permission validation failure and disclosure of P2P preheat execution logs | HIGH | 7.7 | Nov 14, 2024 |
| CVE-2022-31667 | Harbor fails to validate the user permissions when updating a robot account | MEDIUM | 6.4 | Nov 14, 2024 |
| CVE-2022-31669 | Harbor fails to validate the user permissions when updating tag immutability policies | HIGH | 7.7 | Nov 14, 2024 |
| CVE-2022-31670 | Harbor fails to validate the user permissions when updating tag retention policies | HIGH | 7.7 | Nov 14, 2024 |
| CVE-2022-31671 | Harbor fails to validate the user permissions when reading and updating job execution logs through the P2P preheat execution logs | HIGH | 7.4 | Nov 14, 2024 |
| CVE-2022-31666 | Harbor fails to validate user permissions while Viewing, updating and deleting Webhook policies | HIGH | 7.7 | Nov 14, 2024 |
| CVE-2024-22278 | Harbor fails to validate the user permissions when updating project configurations | HIGH | 7.0 | Aug 2, 2024 |
| CVE-2024-22261 | SQL Injection in Harbor scan log API | MEDIUM | 5.5 | Jun 10, 2024 |
| CVE-2024-22244 | Harbor Open Redirect URL | MEDIUM | 6.1 | Jun 10, 2024 |
| CVE-2023-20902 | Timing attack risk in Harbor | MEDIUM | 6.5 | Nov 9, 2023 |
| CVE-2022-46463 | An access control issue in Harbor v1.X.X to v2.5.3 allows attackers to access public and private image repositories without authentication. NOTE: the vendor's… | HIGH | 7.5 | Jan 12, 2023 |
| CVE-2019-19030 | Cloud Native Computing Foundation Harbor before 1.10.3 and 2.x before 2.0.1 allows resource enumeration because unauthenticated API calls reveal (via the HTTP… | MEDIUM | 5.3 | Dec 26, 2022 |
| CVE-2020-29662 | In Harbor 2.0 before 2.0.5 and 2.1.x before 2.1.2 the catalog’s registry API is exposed on an unauthenticated path. | MEDIUM | 5.3 | Feb 2, 2021 |
| CVE-2020-13794 | Harbor 1.9.* 1.10.* and 2.0.* allows Exposure of Sensitive Information to an Unauthorized Actor. | MEDIUM | 4.3 | Sep 29, 2020 |
| CVE-2020-13788 | Harbor prior to 2.0.1 allows SSRF with this limitation: an attacker with the ability to edit projects can scan ports of hosts accessible on the Harbor server's… | MEDIUM | 4.3 | Jul 15, 2020 |
| CVE-2019-19023 | Cloud Native Computing Foundation Harbor prior to 1.8.6 and 1.9.3 has a Privilege Escalation Vulnerability in the VMware Harbor Container Registry for the Pivo… | MEDIUM | 9.3 | Mar 20, 2020 |
| CVE-2019-19029 | Cloud Native Computing Foundation Harbor prior to 1.8.6 and 1.9.3 allows SQL Injection via user-groups in the VMware Harbor Container Registry for the Pivotal… | HIGH | 8.6 | Mar 20, 2020 |
| CVE-2019-19026 | Cloud Native Computing Foundation Harbor prior to 1.8.6 and 1.9.3 allows SQL Injection via project quotas in the VMware Harbor Container Registry for the Pivot… | MEDIUM | 4.9 | Mar 20, 2020 |
| CVE-2019-19025 | Cloud Native Computing Foundation Harbor prior to 1.8.6 and 1.9.3 allows CSRF in the VMware Harbor Container Registry for the Pivotal Platform. | HIGH | 8.8 | Mar 20, 2020 |
| CVE-2019-3990 | A User Enumeration flaw exists in Harbor. The issue is present in the "/users" API endpoint. This endpoint is supposed to be restricted to administrators. This… | MEDIUM | 4.3 | Dec 3, 2019 |
| CVE-2019-16919 | Harbor API has a Broken Access Control vulnerability. The vulnerability allows project administrators to use the Harbor API to create a robot account with unau… | HIGH | 7.5 | Oct 18, 2019 |
| CVE-2019-16097 | core/api/user.go in Harbor 1.7.0 through 1.8.2 allows non-admin users to create admin accounts via the POST /api/users API, when Harbor is setup with DB as aut… | MEDIUM | 6.5 | Sep 8, 2019 |
| CVE-2017-17697 | The Ping() function in ui/api/target.go in Harbor through 1.3.0-rc4 has SSRF via the endpoint parameter to /api/targets/ping. | HIGH | 8.6 | Dec 15, 2017 |
Showing 1 to 24 of 24 CVEs