PT-2020-13680 · Vmware · Harbor

·

CVE-2020-13794

·

Published

2020-09-29

·

Updated

2024-08-21

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Harbor versions 1.9.* through 2.0.*
Description The issue allows exposure of sensitive information to an unauthorized actor. Authenticated users can exploit an enumeration vulnerability in Harbor. The vulnerability is present in the "/users" API endpoint, which is supposed to be restricted to administrators. This restriction can be bypassed, and information can be obtained via the "search" functionality. Non-administrator users can list all usernames and user IDs by sending a GET request to "/api/users/search" with the parameter username and value .
Recommendations For Harbor versions 1.9.* through 2.0.*, update to either version 2.1.0 or 2.0.3 to fix this issue immediately. As a temporary workaround is not available, updating to the patched version is the recommended course of action.

Exploit

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-HARBOR-2020-13794
CVE-2020-13794
GHSA-Q9P8-33WC-H432
GO-2022-0865

Affected Products

Harbor