Vulnerabilities > Linuxfoundation > Harbor > 1.3.0

DATE CVE VULNERABILITY TITLE RISK
2023-11-09 CVE-2023-20902 Race Condition vulnerability in Linuxfoundation Harbor
A timing condition in Harbor 2.6.x and below, Harbor 2.7.2 and below,  Harbor 2.8.2 and below, and Harbor 1.10.17 and below allows an attacker with network access to create jobs/stop job tasks and retrieve job task information.
network
high complexity
linuxfoundation CWE-362
6.5
2023-01-13 CVE-2022-46463 Missing Authentication for Critical Function vulnerability in Linuxfoundation Harbor
An access control issue in Harbor v1.X.X to v2.5.3 allows attackers to access public and private image repositories without authentication.
network
low complexity
linuxfoundation CWE-306
7.5
2020-07-15 CVE-2020-13788 Server-Side Request Forgery (SSRF) vulnerability in Linuxfoundation Harbor
Harbor prior to 2.0.1 allows SSRF with this limitation: an attacker with the ability to edit projects can scan ports of hosts accessible on the Harbor server's intranet.
network
low complexity
linuxfoundation CWE-918
4.0
2017-12-15 CVE-2017-17697 Server-Side Request Forgery (SSRF) vulnerability in Linuxfoundation Harbor
The Ping() function in ui/api/target.go in Harbor through 1.3.0-rc4 has SSRF via the endpoint parameter to /api/targets/ping.
network
low complexity
linuxfoundation CWE-918
5.0