Harbor 1.9.* 1.10.* and 2.0.* allows Exposure of Sensitive Information to an Unauthorized Actor.
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Link | Tags |
---|---|
https://github.com/goharbor/harbor/releases | third party advisory release notes |
https://github.com/goharbor/harbor/security/advisories/GHSA-q9p8-33wc-h432 | patch third party advisory exploit |
https://www.cybereagle.io/blog/cve-2020-13794/ | third party advisory exploit |