Cloud Native Computing Foundation Harbor prior to 1.10.3 and 2.x prior to 2.0.1 allows resource enumeration because unauthenticated API calls reveal (via the HTTP status code) whether a resource exists.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
linuxfoundation harbor |