Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
User permission validation failure and disclosure of P2P preheat execution logs
Vulnerability Description
Harbor fails to validate the user permissions when updating p2p preheat policies. By sending a request to update a p2p preheat policy with an id that belongs to a project that the currently authenticated user doesn't have access to, the attacker could modify p2p preheat policies configured in other projects.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L
Vulnerability Type
授权机制不恰当
Vulnerability Title
Harbor 授权问题漏洞
Vulnerability Description
Harbor是Harbor开源的一个开源注册表。通过策略和基于角色的访问控制来保护工件,确保图像被扫描并且没有漏洞,并将图像签名为可信的。 Harbor存在授权问题漏洞,该漏洞源于更新p2p预热策略时未验证用户权限,导致攻击者可以修改其他项目中配置的p2p预热策略。
CVSS Information
N/A
Vulnerability Type
N/A