Harbor是Harbor开源的一个开源注册表。通过策略和基于角色的访问控制来保护工件,确保图像被扫描并且没有漏洞,并将图像签名为可信的。 Harbor V1.X.X至v2.5.3版本、V2.6.0版本存在安全漏洞,攻击者利用该漏洞可以在未授权的情况下访问私有和公共镜像仓库的所有信息,拉取镜像。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | CVE-2022-46463(Harbor 未授权) | https://github.com/nu0l/CVE-2022-46463 | POC Details |
| 2 | harbor unauthorized detection | https://github.com/404tk/CVE-2022-46463 | POC Details |
| 3 | CVE-2022-46463 harbor公开镜像全自动下载脚本 | https://github.com/CodeSecurityTeam/harbor | POC Details |
| 4 | An access control issue in Harbor v1.X.X to v2.5.3 allows attackers to access public and private image repositories without authentication | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2022/CVE-2022-46463.yaml | POC Details |
| 5 | None | https://github.com/Threekiii/Awesome-POC/blob/master/Web%E5%BA%94%E7%94%A8%E6%BC%8F%E6%B4%9E/Harbor%20%E5%85%AC%E5%BC%80%E9%95%9C%E5%83%8F%E4%BB%93%E5%BA%93%E6%9C%AA%E6%8E%88%E6%9D%83%E8%AE%BF%E9%97%AE%20CVE-2022-46463.md | POC Details |
| 6 | This is an improved PoC version of the CVE-2022-46463 vulnerability identified in Harbor software. | https://github.com/sevbandonmez/harbor-stalker | POC Details |
No public POC found.
Login to generate AI POC| CVE-2023-0243 | 6.3 MEDIUM | TuziCMS Article Module ArticleController.class.php index sql injection |
| CVE-2023-0244 | 6.3 MEDIUM | TuziCMS KefuController.class.php delall sql injection |
| CVE-2022-24913 | 5.5 MEDIUM | java-merge-sort 安全漏洞 |
| CVE-2023-23455 | Linux kernel 安全漏洞 | |
| CVE-2023-23454 | Linux kernel 安全漏洞 | |
| CVE-2022-4842 | Linux kernel 代码问题漏洞 | |
| CVE-2022-47927 | MediaWiki 安全漏洞 | |
| CVE-2022-4743 | SDL 安全漏洞 | |
| CVE-2022-47102 | Student Study Center Management System 跨站脚本漏洞 | |
| CVE-2022-46623 | Judging Management System SQL注入漏洞 | |
| CVE-2022-46622 | Judging Management System 跨站脚本漏洞 | |
| CVE-2022-46503 | Online Student Enrollment System 跨站脚本漏洞 | |
| CVE-2022-46472 | Helm和Helmet Store Showroom Site SQL注入漏洞 | |
| CVE-2022-46438 | DouCo DouPHP 跨站脚本漏洞 | |
| CVE-2022-45729 | Doctor Appointment Management System 跨站脚本漏洞 | |
| CVE-2022-45728 | Doctor Appointment Management System 跨站脚本漏洞 | |
| CVE-2022-42704 | ServiceNow San Diego Patch和Rome Patch 跨站脚本漏洞 | |
| CVE-2022-3977 | Linux kernel 资源管理错误漏洞 | |
| CVE-2022-3628 | Linux kernel 缓冲区错误漏洞 | |
| CVE-2022-3592 | Samba 后置链接漏洞 |
Showing top 20 of 26 CVEs. View all on vendor page → →
No comments yet