Harbor是Harbor开源的一个开源注册表。通过策略和基于角色的访问控制来保护工件,确保图像被扫描并且没有漏洞,并将图像签名为可信的。 Harbor存在授权问题漏洞,该漏洞源于在通过P2P预热执行日志读取和更新作业执行日志时未验证用户权限,导致攻击者可以读取作业日志。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | Harbor | Harbor (Go) 2.x<=2.4.2; 2.5<=2.5.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2024-10979 | 8.8 HIGH | PostgreSQL PL/Perl environment variable changes execute arbitrary code |
| CVE-2022-31666 | 7.7 HIGH | Harbor fails to validate user permissions while Viewing, updating and deleting Webhook pol |
| CVE-2022-31670 | 7.7 HIGH | Harbor fails to validate the user permissions when updating tag retention policies |
| CVE-2022-31668 | 7.4 HIGH | User permission validation failure and disclosure of P2P preheat execution logs |
| CVE-2022-31669 | 6.4 MEDIUM | Harbor fails to validate the user permissions when updating tag immutability policies |
| CVE-2022-31667 | 6.4 MEDIUM | Harbor fails to validate the user permissions when updating a robot account |
| CVE-2024-11210 | 5.4 MEDIUM | EyouCMS FilemanagerLogic.php editFile path traversal |
| CVE-2024-11211 | 4.7 MEDIUM | EyouCMS Website Logo unrestricted upload |
| CVE-2024-10976 | 4.2 MEDIUM | PostgreSQL row security below e.g. subqueries disregards user ID changes |
| CVE-2024-10978 | 4.2 MEDIUM | PostgreSQL SET ROLE, SET SESSION AUTHORIZATION reset to wrong user ID |
| CVE-2024-10977 | 3.1 LOW | PostgreSQL libpq retains an error message from man-in-the-middle |
| CVE-2024-50827 | Kashipara E-learning Management System 安全漏洞 | |
| CVE-2024-50835 | Kashipara E-learning Management System 安全漏洞 | |
| CVE-2024-50824 | Kashipara E-learning Management System 安全漏洞 | |
| CVE-2024-50833 | Kashipara E-learning Management System 安全漏洞 | |
| CVE-2024-50830 | Kashipara E-learning Management System 安全漏洞 | |
| CVE-2024-40579 | Virtuozzo Hybrid Server For WHMCS 安全漏洞 | |
| CVE-2024-52613 | tsMuxer 安全漏洞 | |
| CVE-2024-50836 | Kashipara E-learning Management System 安全漏洞 | |
| CVE-2024-50825 | Kashipara E-learning Management System 安全漏洞 |
Showing top 20 of 46 CVEs. View all on vendor page → →
No comments yet