CVE-2022-31668
Vulnerability Summary
Timeline
Description
Harbor fails to validate the user permissions when updating p2p preheat policies. By sending a request to update a p2p preheat policy with an id that belongs to a project that the currently authenticated user doesn't have access to, the attacker could modify p2p preheat policies configured in other projects.
CVSS Metrics
- v3.1•HIGH•Score: 7.4CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L
- v3.1•HIGH•Score: 7.7CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N
EPSS Trends
Current EPSS score: 0.06%• Percentile: 17%
Techniques & Countermeasures
- CWE-285•Improper Authorization
The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.
- CWE-863•Incorrect Authorization
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.
Affected Systems
- github.com/goharbor•harbor
≥ 2.0.0, < 2.4.3 | ≥ 2.5.0, < 2.5.2 | ≥ 2.5.0+incompatible, < 2.5.2+incompatible
- github.com/goharbor/harbor•src
< 0.0.0-20220630175814-b4ef1db
- linuxfoundation•harbor
≥ 2.0.0, < 2.4.3 | ≥ 2.5.0, < 2.5.2