Vulnerabilities > CVE-2017-17697 - Server-Side Request Forgery (SSRF) vulnerability in Linuxfoundation Harbor

047910
CVSS 8.6 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
NONE
Availability impact
NONE
network
low complexity
linuxfoundation
CWE-918

Summary

The Ping() function in ui/api/target.go in Harbor through 1.3.0-rc4 has SSRF via the endpoint parameter to /api/targets/ping.

Common Weakness Enumeration (CWE)