Application Security - harbaor - Vulnerability Summary

CVE-2019-19026 (SQL injection, high risk): https://github.com/goharbor/harbor/security/advisories/GHSA-rh89-vvrg-fg64 (administrative rights required)
CVE-2019-19029 (SQL injection, high risk): https://github.com/goharbor/harbor/security/advisories/GHSA-qcfv-8v29-469w  (administrative rights required)
CVE-2019-19025 (CSRF protection is missing, severe): https://github.com/goharbor/harbor/security/advisories/GHSA-gcqm-v682-ccw6 (to be induced authorization)
CVE-2019-19023 (privilege escalation, serious): https://github.com/goharbor/harbor/security/advisories/GHSA-3868-7c5x-4827 (permission required)
CVE-2019-3990 (user enumeration, medium risk): https://github.com/goharbor/harbor/security/advisories/GHSA-6qj9-33j4-rvhg (to be ordinary user permissions)

Guess you like

Origin www.cnblogs.com/AtesetEnginner/p/12016121.html
Recommended