Show filters
25 Total Results
Displaying 11-20 of 25
Sort by:
Attacker Value
Unknown

CVE-2023-20902

Disclosure Date: November 09, 2023 (last updated November 17, 2023)
A timing condition in Harbor 2.6.x and below, Harbor 2.7.2 and below,  Harbor 2.8.2 and below, and Harbor 1.10.17 and below allows an attacker with network access to create jobs/stop job tasks and retrieve job task information.
Attacker Value
Unknown

CVE-2023-5252

Disclosure Date: October 30, 2023 (last updated November 09, 2023)
The FareHarbor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcodes in versions up to, and including, 3.6.7 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Attacker Value
Unknown

CVE-2023-25021

Disclosure Date: May 08, 2023 (last updated October 08, 2023)
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in FareHarbor FareHarbor for WordPress plugin <= 3.6.6 versions.
Attacker Value
Unknown

CVE-2022-46463

Disclosure Date: January 13, 2023 (last updated November 08, 2023)
An access control issue in Harbor v1.X.X to v2.5.3 allows attackers to access public and private image repositories without authentication. NOTE: the vendor's position is that this "is clearly described in the documentation as a feature."
Attacker Value
Unknown

CVE-2019-19030

Disclosure Date: December 26, 2022 (last updated October 08, 2023)
Cloud Native Computing Foundation Harbor before 1.10.3 and 2.x before 2.0.1 allows resource enumeration because unauthenticated API calls reveal (via the HTTP status code) whether a resource exists.
Attacker Value
Unknown

CVE-2020-29662

Disclosure Date: February 02, 2021 (last updated February 22, 2025)
In Harbor 2.0 before 2.0.5 and 2.1.x before 2.1.2 the catalog’s registry API is exposed on an unauthenticated path.
Attacker Value
Unknown

CVE-2020-13794

Disclosure Date: September 30, 2020 (last updated February 22, 2025)
Harbor 1.9.* 1.10.* and 2.0.* allows Exposure of Sensitive Information to an Unauthorized Actor.
Attacker Value
Unknown

CVE-2020-13788

Disclosure Date: July 15, 2020 (last updated February 21, 2025)
Harbor prior to 2.0.1 allows SSRF with this limitation: an attacker with the ability to edit projects can scan ports of hosts accessible on the Harbor server's intranet.
Attacker Value
Unknown

CVE-2019-19029

Disclosure Date: March 20, 2020 (last updated February 21, 2025)
Cloud Native Computing Foundation Harbor prior to 1.8.6 and 1.9.3 allows SQL Injection via user-groups in the VMware Harbor Container Registry for the Pivotal Platform.
Attacker Value
Unknown

CVE-2019-19026

Disclosure Date: March 20, 2020 (last updated February 21, 2025)
Cloud Native Computing Foundation Harbor prior to 1.8.6 and 1.9.3 allows SQL Injection via project quotas in the VMware Harbor Container Registry for the Pivotal Platform.