Vulnerability Description
Harbor fails to validate the user permissions when updating a robot account that belongs to a project that the authenticated user doesn’t have access to. By sending a request that attempts to update a robot account, and specifying a robot account id and robot account name that belongs to a different project that the user doesn’t have access to, it was possible to revoke the robot account permissions.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Linuxfoundation | Harbor | >= 2.0.0, < 2.4.3 |
Related Weaknesses (CWE)
References
FAQ
What is CVE-2022-31667?
CVE-2022-31667 is a vulnerability with a CVSS score of 6.4 (MEDIUM). Harbor fails to validate the user permissions when updating a robot account that belongs to a project that the authenticated user doesn’t have access to. By sending a request that attempts to update...
How severe is CVE-2022-31667?
CVE-2022-31667 has been rated MEDIUM with a CVSS base score of 6.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-31667?
Check the references section above for vendor advisories and patch information. Affected products include: Linuxfoundation Harbor.