Unauthenticated API Exposure in Harbor by VMware
CVE-2020-29662
5.3MEDIUM
Summary
In certain versions of Harbor software, specifically version 2.0 prior to 2.0.5 and 2.1.x prior to 2.1.2, the catalog's registry API is available through an unauthenticated path. This exposure could allow unauthorized users to access potentially sensitive data without the need for valid authentication credentials.
References
CVSS V3.1
Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved