Malicious User Access to Job Logs via Unvalidated User Permissions
CVE-2022-31671
7.4HIGH
What is CVE-2022-31671?
A security vulnerability in Harbor allows authenticated users to bypass authorization measures when accessing job execution logs. Specifically, the flaw arises from Harbor's failure to validate user permissions during the reading and updating of P2P preheat execution logs. By crafting requests that specify various job IDs, malicious users can gain unauthorized access to job logs stored within the Harbor database, potentially exposing sensitive operational information. This risk necessitates immediate attention to ensure robust access control measures are implemented.
Affected Version(s)
Harbor Harbor (Go) 2.x<=2.4.2; 2.5<=2.5.1