PT-2021-11705 · Harbor · Harbor
Javier Provecho
·
Published
2021-02-02
·
Updated
2024-08-21
·
CVE-2020-29662
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
Harbor versions 2.0 through 2.0.4
Harbor versions 2.1.x through 2.1.1
Description:
The catalog's registry API is exposed on an unauthenticated path, allowing bypass of authorization. The vulnerable API endpoint is "GET /v2/ catalog/" which can be accessed without authentication by adding a trailing slash to the path.
Recommendations:
For Harbor versions 2.0 through 2.0.4, update to version 2.0.5 to fix this issue immediately.
For Harbor versions 2.1.x through 2.1.1, update to version 2.1.2 to fix this issue immediately.
As a temporary workaround, consider disabling the vulnerable API endpoint or redirecting it to a 404 sink hole in the ingress if updating to a patched version is not possible.
Fix
Cleartext Transmission of Sensitive Information
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Harbor