5
CVSSv2

CVE-2019-16919

Published: 18/10/2019 Updated: 01/04/2020
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

Harbor API has a Broken Access Control vulnerability. The vulnerability allows project administrators to use the Harbor API to create a robot account with unauthorized push and/or pull access permissions to a project they don't have access or control for. The Harbor API did not enforce the proper project permissions and project scope on the API request to create a new robot account.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

linuxfoundation harbor

linuxfoundation harbor 1.9.0

vmware harbor container registry

vmware cloud foundation -