Attackers Can Modify P2P Preheat Policies in Other Projects via ID Confusion
CVE-2022-31668
What is CVE-2022-31668?
A security issue exists in Harbor where the system fails to adequately validate user permissions when an authenticated user attempts to update p2p preheat policies. This can be exploited by an attacker who sends a request to modify a policy using an ID that belongs to a project that should be restricted. As a result, unauthorized changes may be made to p2p preheat configurations in projects that the attacker does not have legitimate access to, posing a potential risk to data integrity and security across affected applications.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Harbor Harbor (Go) 2.x<=2.4.2; 2.5<=2.5.1
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
