By sending a request to update a tag retention policy with an id that belongs to a project that the currently authenticated user doesn’t have access to, the attacker could modify
tag retention policies configured in other projects.
No analysis available yet.
No remediation available yet.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-6672 | Harbor fails to validate the user permissions when updating tag retention policies. By sending a request to update a tag retention policy with an id that belongs to a project that the currently authenticated user doesn’t have access to, the attacker could modify tag retention policies configured in other projects. |
Github GHSA |
GHSA-3637-v6vq-xqqw | Harbor fails to validate the user permissions when updating tag retention policies |
Tue, 19 Nov 2024 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Linuxfoundation
Linuxfoundation harbor |
|
| Weaknesses | CWE-863 | |
| CPEs | cpe:2.3:a:linuxfoundation:harbor:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Linuxfoundation
Linuxfoundation harbor |
Thu, 14 Nov 2024 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 14 Nov 2024 12:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Harbor fails to validate the user permissions when updating tag retention policies. By sending a request to update a tag retention policy with an id that belongs to a project that the currently authenticated user doesn’t have access to, the attacker could modify tag retention policies configured in other projects. | |
| Title | Harbor fails to validate the user permissions when updating tag retention policies | |
| Weaknesses | CWE-285 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: vmware
Published:
Updated: 2024-11-14T14:09:48.571Z
Reserved: 2022-05-25T23:31:47.419Z
Link: CVE-2022-31670
Updated: 2024-11-14T14:09:35.315Z
Status : Analyzed
Published: 2024-11-14T12:15:17.040
Modified: 2024-11-19T15:20:54.243
Link: CVE-2022-31670
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA