An access control issue in Harbor v1.X.X to v2.5.3 allows attackers to access public and private image repositories without authentication. NOTE: the vendor's position is that this "is clearly described in the documentation as a feature."
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
Link | Tags |
---|---|
https://github.com/lanqingaa/123/blob/main/README.md | third party advisory |
https://github.com/lanqingaa/123/tree/bb48caa844d88b0e41e69157f2a2734311abf02d | broken link |
https://github.com/Vad1mo | third party advisory |