PT-2019-14506 · Vmware · Harbor

Aviv Sasson

·

Published

2019-09-08

·

Updated

2024-08-21

·

CVE-2019-16097

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Harbor versions 1.7.0 through 1.8.2
Description The issue allows non-admin users to create admin accounts via the "POST /api/users" API endpoint, when Harbor is set up with a DB as the authentication backend and allows users to do self-registration. This enables privilege escalation from a non-admin to an admin account.
Recommendations For Harbor versions 1.7.0 through 1.8.2, update to version 1.7.6, 1.8.3, or 1.9.0 to resolve the issue. As a temporary workaround, consider configuring Harbor to use a non-DB authentication backend such as LDAP.

Exploit

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2019-16097
GHSA-9WVH-FF5F-XJPJ
GO-2022-0818

Affected Products

Harbor