CVE-2022-31666

Harbor fails to validate user permissions while deleting Webhook policies, allowing malicious users to view, update and delete Webhook policies of other users.  The attacker could modify Webhook policies configured in other projects.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:linuxfoundation:harbor:*:*:*:*:*:*:*:*
cpe:2.3:a:linuxfoundation:harbor:*:*:*:*:*:*:*:*

History

20 Feb 2025, 20:06

Type Values Removed Values Added
References () https://github.com/goharbor/harbor/security/advisories/GHSA-8hwq-5f22-jfr3 - () https://github.com/goharbor/harbor/security/advisories/GHSA-8hwq-5f22-jfr3 - Vendor Advisory
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.4
CPE cpe:2.3:a:linuxfoundation:harbor:*:*:*:*:*:*:*:*
First Time Linuxfoundation
Linuxfoundation harbor
CWE CWE-862

14 Nov 2024, 12:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-11-14 12:15

Updated : 2025-02-20 20:06


NVD link : CVE-2022-31666

Mitre link : CVE-2022-31666


JSON object : View

Products Affected

linuxfoundation

  • harbor
CWE
CWE-862

Missing Authorization