Vulnerabilities > Linuxfoundation

DATE CVE VULNERABILITY TITLE RISK
2024-11-14 CVE-2022-31667 Incorrect Authorization vulnerability in Linuxfoundation Harbor
Harbor fails to validate the user permissions when updating a robot account that belongs to a project that the authenticated user doesn’t have access to.  By sending a request that attempts to update a robot account, and specifying a robot account id and robot account name that belongs to a different project that the user doesn’t have access to, it was possible to revoke the robot account permissions.
network
low complexity
linuxfoundation CWE-863
6.4
2024-11-14 CVE-2022-31668 Incorrect Authorization vulnerability in Linuxfoundation Harbor
Harbor fails to validate the user permissions when updating p2p preheat policies. By sending a request to update a p2p preheat policy with an id that belongs to a project that the currently authenticated user doesn't have access to, the attacker could modify p2p preheat policies configured in other projects.
network
low complexity
linuxfoundation CWE-863
7.7
2024-11-14 CVE-2022-31669 Incorrect Authorization vulnerability in Linuxfoundation Harbor
Harbor fails to validate the user permissions when updating tag immutability policies.  By sending a request to update a tag immutability policy with an id that belongs to a project that the currently authenticated user doesn’t have access to, the attacker could modify tag immutability policies configured in other projects.
network
low complexity
linuxfoundation CWE-863
7.7
2024-11-14 CVE-2022-31670 Incorrect Authorization vulnerability in Linuxfoundation Harbor
Harbor fails to validate the user permissions when updating tag retention policies.  By sending a request to update a tag retention policy with an id that belongs to a project that the currently authenticated user doesn’t have access to, the attacker could modify tag retention policies configured in other projects.
network
low complexity
linuxfoundation CWE-863
7.7
2024-11-14 CVE-2022-31671 Incorrect Authorization vulnerability in Linuxfoundation Harbor
Harbor fails to validate user permissions when reading and updating job execution logs through the P2P preheat execution logs.
network
low complexity
linuxfoundation CWE-863
7.4
2024-10-10 CVE-2024-9798 Cleartext Storage of Sensitive Information vulnerability in Linuxfoundation Zowe API Mediation Layer
The health endpoint is public so everybody can see a list of all services.
network
low complexity
linuxfoundation CWE-312
5.3
2024-10-10 CVE-2024-9802 Cleartext Storage of Sensitive Information vulnerability in Linuxfoundation Zowe API Mediation Layer
The conformance validation endpoint is public so everybody can verify the conformance of onboarded services.
network
low complexity
linuxfoundation CWE-312
5.3
2024-09-19 CVE-2023-27584 Use of Hard-coded Credentials vulnerability in Linuxfoundation Dragonfly
Dragonfly is an open source P2P-based file distribution and image acceleration system.
network
low complexity
linuxfoundation CWE-798
critical
9.8
2024-09-02 CVE-2024-20084 Out-of-bounds Read vulnerability in multiple products
In power, there is a possible out of bounds read due to a missing bounds check.
4.4
2024-09-02 CVE-2024-20085 Out-of-bounds Read vulnerability in multiple products
In power, there is a possible out of bounds read due to a missing bounds check.
4.4