Vulnerability Description
Harbor fails to validate user permissions when reading and updating job execution logs through the P2P preheat execution logs. By sending a request that attempts to read/update P2P preheat execution logs and specifying different job IDs, malicious authenticated users could read all the job logs stored in the Harbor database.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Linuxfoundation | Harbor | >= 2.0.0, < 2.4.3 |
Related Weaknesses (CWE)
References
- https://github.com/goharbor/harbor/security/advisories/GHSA-3wpx-625q-22j7Vendor Advisory
- https://github.com/goharbor/harbor/security/advisories/GHSA-q76q-q8hw-hmpwVendor Advisory
FAQ
What is CVE-2022-31671?
CVE-2022-31671 is a vulnerability with a CVSS score of 7.4 (HIGH). Harbor fails to validate user permissions when reading and updating job execution logs through the P2P preheat execution logs. By sending a request that attempts to read/update P2P preheat execution l...
How severe is CVE-2022-31671?
CVE-2022-31671 has been rated HIGH with a CVSS base score of 7.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-31671?
Check the references section above for vendor advisories and patch information. Affected products include: Linuxfoundation Harbor.