Vulnerability Description
Cloud Native Computing Foundation Harbor prior to 1.8.6 and 1.9.3 allows SQL Injection via user-groups in the VMware Harbor Container Registry for the Pivotal Platform.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Linuxfoundation | Harbor | >= 1.7.0, < 1.8.6 |
| Pivotal | Vmware Harbor Registry | - |
Related Weaknesses (CWE)
References
- https://github.com/goharbor/harbor/security/advisoriesThird Party Advisory
- https://github.com/goharbor/harbor/security/advisories/GHSA-qcfv-8v29-469wThird Party Advisory
- https://tanzu.vmware.com/security/cve-2019-19029Third Party Advisory
- https://github.com/goharbor/harbor/security/advisoriesThird Party Advisory
- https://github.com/goharbor/harbor/security/advisories/GHSA-qcfv-8v29-469wThird Party Advisory
- https://tanzu.vmware.com/security/cve-2019-19029Third Party Advisory
FAQ
What is CVE-2019-19029?
CVE-2019-19029 is a vulnerability with a CVSS score of 7.2 (HIGH). Cloud Native Computing Foundation Harbor prior to 1.8.6 and 1.9.3 allows SQL Injection via user-groups in the VMware Harbor Container Registry for the Pivotal Platform.
How severe is CVE-2019-19029?
CVE-2019-19029 has been rated HIGH with a CVSS base score of 7.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-19029?
Check the references section above for vendor advisories and patch information. Affected products include: Linuxfoundation Harbor, Pivotal Vmware Harbor Registry.