Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%
Get alerts for future matching vulnerabilitiesLog in to subscribe
I. Basic Information for CVE-2022-46463
Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
An access control issue in Harbor v1.X.X to v2.5.3 allows attackers to access public and private image repositories without authentication. NOTE: the vendor's position is that this "is clearly described in the documentation as a feature."
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
Harbor 访问控制错误漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Harbor是Harbor开源的一个开源注册表。通过策略和基于角色的访问控制来保护工件,确保图像被扫描并且没有漏洞,并将图像签名为可信的。 Harbor V1.X.X至v2.5.3版本、V2.6.0版本存在安全漏洞,攻击者利用该漏洞可以在未授权的情况下访问私有和公共镜像仓库的所有信息,拉取镜像。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)
Affected Products
VendorProductAffected VersionsCPESubscribe
-n/a n/a -
II. Public POCs for CVE-2022-46463
#POC DescriptionSource LinkShenlong Link
1CVE-2022-46463(Harbor 未授权)https://github.com/nu0l/CVE-2022-46463POC Details
2harbor unauthorized detectionhttps://github.com/404tk/CVE-2022-46463POC Details
3CVE-2022-46463 harbor公开镜像全自动下载脚本https://github.com/CodeSecurityTeam/harborPOC Details
4An access control issue in Harbor v1.X.X to v2.5.3 allows attackers to access public and private image repositories without authentication https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2022/CVE-2022-46463.yamlPOC Details
5Nonehttps://github.com/Threekiii/Awesome-POC/blob/master/Web%E5%BA%94%E7%94%A8%E6%BC%8F%E6%B4%9E/Harbor%20%E5%85%AC%E5%BC%80%E9%95%9C%E5%83%8F%E4%BB%93%E5%BA%93%E6%9C%AA%E6%8E%88%E6%9D%83%E8%AE%BF%E9%97%AE%20CVE-2022-46463.mdPOC Details
6This is an improved PoC version of the CVE-2022-46463 vulnerability identified in Harbor software.https://github.com/sevbandonmez/harbor-stalkerPOC Details
AI-Generated POCPremium

No public POC found.

Login to generate AI POC
III. Intelligence Information for CVE-2022-46463
Please Login to view more intelligence information
IV. Related Vulnerabilities
V. Comments for CVE-2022-46463

No comments yet


Leave a comment