PT-2021-11705 · Harbor · Harbor

Javier Provecho

·

Published

2021-02-02

·

Updated

2024-08-21

·

CVE-2020-29662

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions: Harbor versions 2.0 through 2.0.4 Harbor versions 2.1.x through 2.1.1
Description: The catalog's registry API is exposed on an unauthenticated path, allowing bypass of authorization. The vulnerable API endpoint is "GET /v2/ catalog/" which can be accessed without authentication by adding a trailing slash to the path.
Recommendations: For Harbor versions 2.0 through 2.0.4, update to version 2.0.5 to fix this issue immediately. For Harbor versions 2.1.x through 2.1.1, update to version 2.1.2 to fix this issue immediately. As a temporary workaround, consider disabling the vulnerable API endpoint or redirecting it to a 404 sink hole in the ingress if updating to a patched version is not possible.

Fix

Cleartext Transmission of Sensitive Information

Improper Authentication

Weakness Enumeration

Related Identifiers

BIT-HARBOR-2020-29662
CVE-2020-29662
GHSA-38R5-34MR-MVM7
GO-2022-0785

Affected Products

Harbor