A User Enumeration flaw exists in Harbor. The issue is present in the "/users" API endpoint. This endpoint is supposed to be restricted to administrators. This restriction is able to be bypassed and information can be obtained about registered users can be obtained via the "search" functionality.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: tenable

Published: 2019-12-03T16:55:15

Updated: 2024-08-04T19:26:27.642Z

Reserved: 2019-01-03T00:00:00

Link: CVE-2019-3990

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2019-12-03T17:15:11.727

Modified: 2020-08-24T17:37:01.140

Link: CVE-2019-3990

cve-icon Redhat

No data.