Broken Access Control in VMware Harbor API
CVE-2019-16919

7.5HIGH

Key Information:

Vendor
Linux
Status
Vendor
CVE Published:
18 October 2019

Summary

The Harbor API is susceptible to a broken access control vulnerability that enables project administrators to create robot accounts with unauthorized access permissions. This means that users, who lack the proper project permissions, can utilize the API to generate robot accounts that gain push and/or pull access to projects beyond their control. The API does not adequately enforce project permissions, leading to potential exposure of sensitive project data and resources.

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.