Broken Access Control in VMware Harbor API
CVE-2019-16919
7.5HIGH
Summary
The Harbor API is susceptible to a broken access control vulnerability that enables project administrators to create robot accounts with unauthorized access permissions. This means that users, who lack the proper project permissions, can utilize the API to generate robot accounts that gain push and/or pull access to projects beyond their control. The API does not adequately enforce project permissions, leading to potential exposure of sensitive project data and resources.
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved