Malicious User Access to Job Logs via Unvalidated User Permissions
CVE-2022-31671
What is CVE-2022-31671?
A security vulnerability in Harbor allows authenticated users to bypass authorization measures when accessing job execution logs. Specifically, the flaw arises from Harbor's failure to validate user permissions during the reading and updating of P2P preheat execution logs. By crafting requests that specify various job IDs, malicious users can gain unauthorized access to job logs stored within the Harbor database, potentially exposing sensitive operational information. This risk necessitates immediate attention to ensure robust access control measures are implemented.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Harbor Harbor (Go) 2.x<=2.4.2; 2.5<=2.5.1
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
