HIGH 7.4 Go
Harbor fails to validate the user permissions when updating p2p preheat policies
GHSA-r864-28pw-8682 · BIT-harbor-2022-31668 · CVE-2022-31668 · GHSA-3wpx-625q-22j7 · GO-2024-3268
Published · Modified
Description
Harbor fails to validate the user permissions when updating p2p preheat policies. By sending a request to update a p2p preheat policy with an id that belongs to a project that the currently authenticated user doesn't have access to, the attacker could modify p2p preheat policies configured in other projects.
Ready to move
Start Securing
Free, no credit card | First findings in minutes