Attackers Can Modify P2P Preheat Policies in Other Projects via ID Confusion
CVE-2022-31668

7.7HIGH

Key Information:

Vendor

Harbor

Status
Vendor
CVE Published:
14 November 2024

What is CVE-2022-31668?

A security issue exists in Harbor where the system fails to adequately validate user permissions when an authenticated user attempts to update p2p preheat policies. This can be exploited by an attacker who sends a request to modify a policy using an ID that belongs to a project that should be restricted. As a result, unauthorized changes may be made to p2p preheat configurations in projects that the attacker does not have legitimate access to, posing a potential risk to data integrity and security across affected applications.

Affected Version(s)

Harbor Harbor (Go) 2.x<=2.4.2; 2.5<=2.5.1

References

CVSS V3.1

Score:
7.7
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.