PT-2026-94048 · Git+1 · Harbor
CVSS v4.0
7.1
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Harbor versions prior to 2.15.3
Description
Project administrators can recover the scanner adapter secret one character at a time by exploiting fuzzy filtering on the
AccessCredential column. This is possible because the software fails to properly restrict the q query parameter filtering on scanner registration access credentials, allowing the secret to be leaked through response row counts.Recommendations
Update Harbor to version 2.15.3 or later.
Exploit
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Harbor