Lucene search

K
osvGoogleOSV:BIT-HARBOR-2022-46463
HistoryMar 06, 2024 - 10:53 a.m.

BIT-harbor-2022-46463

2024-03-0610:53:25
Google
osv.dev
6
access control
harbor v1.x.x
v2.5.3
unauthorized access
documentation

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

7 High

AI Score

Confidence

Low

0.076 Low

EPSS

Percentile

94.2%

An access control issue in Harbor v1.X.X to v2.5.3 allows attackers to access public and private image repositories without authentication. NOTE: the vendor’s position is that this “is clearly described in the documentation as a feature.”

CPENameOperatorVersion
harborge1.1.0
harborlt2.5.3

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

7 High

AI Score

Confidence

Low

0.076 Low

EPSS

Percentile

94.2%

Related for OSV:BIT-HARBOR-2022-46463