Impact
Harbor through version 2.15.2 allows a project administrator to exfiltrate the scanner adapter secret by manipulating the q query parameter in the scanner registration API. The vulnerable filtering logic interprets the parameter in a fuzzy manner, letting an adversary submit trial values that are compared against the AccessCredential column. For each request, the response row count indicates whether a partial match exists, enabling the attacker to recover the secret one character at a time. The result is a full disclosure of the scanner’s authentication token, which could be used to perform unauthorized scans or to impersonate the scanner service. This flaw reflects improper information disclosure (CWE‑200).
Affected Systems
The vulnerable product is Harbor, the open source container registry maintained by the Linux Foundation. Versions up to and including 2.15.2 are affected. Administrators of Harbor installations using these releases need to verify the exact version and apply the appropriate fix.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity vulnerability, while the EPSS score of less than 1% suggests a very low but non-zero probability of exploitation at the time of assessment. The flaw can be exploited remotely by anyone with project administrator privileges, as it operates through an HTTP query parameter. Because the vulnerability requires interaction with the API endpoint, it is not a purely passive weakness. The vulnerability is not currently listed in the CISA KEV catalog, meaning there is no confirmed exploitation in the wild as of this assessment.
OpenCVE Enrichment