Vulnerabilities > CVE-2022-31666 - Missing Authorization vulnerability in Linuxfoundation Harbor

047910
CVSS 5.4 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
LOW
Confidentiality impact
LOW
Integrity impact
LOW
Availability impact
NONE
network
low complexity
linuxfoundation
CWE-862

Summary

Harbor fails to validate user permissions while deleting Webhook policies, allowing malicious users to view, update and delete Webhook policies of other users.  The attacker could modify Webhook policies configured in other projects.

Common Weakness Enumeration (CWE)