Critical Vulnerability in Harbor...

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

### Executive Summary Aviv Sasson, a security researcher from the cloud division of Unit 42, has identified a critical vulnerability in a widespread cloud native registry called Harbor. The vulnerability allows attackers to take over Harbor registries by sending them a malicious request. The maintainers of Harbor released a patch that closes this critical security hole. Versions 1.7.6 and 1.8.3 include this fix. Unit 42 has found 1,300 Harbor registries open to the internet with vulnerable default settings, which are currently at risk until they’re updated. ### Background As part of our initiative to contribute to and improve Cloud Native Computing Foundation (CNCF) projects, I recently looked at the Harbor project. I found a critical privilege escalation vulnerability that allows anyone to gain admin permissions under its default settings. The vulnerability had been assigned CVE-2019-16097, which was made public on September 10. Harbor is an open source cloud native registry that...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息