Vulnerabilities > CVE-2022-31670 - Incorrect Authorization vulnerability in Linuxfoundation Harbor

047910
CVSS 7.7 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
LOW
Confidentiality impact
NONE
Integrity impact
HIGH
Availability impact
NONE
network
low complexity
linuxfoundation
CWE-863

Summary

Harbor fails to validate the user permissions when updating tag retention policies.  By sending a request to update a tag retention policy with an id that belongs to a project that the currently authenticated user doesn’t have access to, the attacker could modify tag retention policies configured in other projects.

Vulnerable Configurations

Part Description Count
Application
Linuxfoundation
183

Common Weakness Enumeration (CWE)