PT-2022-20879 · Harbor · Harbor

Daniel Abeles

+1

·

Published

2022-09-16

·

Updated

2026-01-26

·

CVE-2022-31666

CVSS v3.1

7.7

High

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Harbor versions prior to 2.5.2
Description The issue allows malicious users to view, update, and delete Webhook policies of other users due to a failure in validating user permissions. This can be exploited through the API endpoint "GET /projects/{project name or id}/webhook/policies/{webhook policy id}" by specifying different Webhook policy IDs. The attacker could modify Webhook policies configured in other projects.
Recommendations For Harbor versions prior to 2.5.2, upgrade to Harbor v2.5.2 or later as soon as possible. As a temporary workaround, consider restricting access to the API endpoint "GET /projects/{project name or id}/webhook/policies/{webhook policy id}" to minimize the risk of exploitation.

Fix

Improper Authorization

Weakness Enumeration

Related Identifiers

BIT-HARBOR-2022-31666
CVE-2022-31666
GHSA-8HWQ-5F22-JFR3
GHSA-JF8P-3VJH-PQ94

Affected Products

Harbor