Attackers Can Modify P2P Preheat Policies in Other Projects via ID Confusion
CVE-2022-31668
7.7HIGH
What is CVE-2022-31668?
A security issue exists in Harbor where the system fails to adequately validate user permissions when an authenticated user attempts to update p2p preheat policies. This can be exploited by an attacker who sends a request to modify a policy using an ID that belongs to a project that should be restricted. As a result, unauthorized changes may be made to p2p preheat configurations in projects that the attacker does not have legitimate access to, posing a potential risk to data integrity and security across affected applications.
Affected Version(s)
Harbor Harbor (Go) 2.x<=2.4.2; 2.5<=2.5.1