ZeroHour

CVE-2022-31666

CVSS 3.1
5.4 medium
EPSS
<1%p41
Published
()
Modified
Description

Harbor fails to validate user permissions while deleting Webhook policies, allowing malicious users to view, update and delete Webhook policies of other users. The attacker could modify Webhook policies configured in other projects.

Vendors
linuxfoundation
Products
harbor
Weakness
CWE-285, CWE-862
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N

In the news