Launch Week Day 1: Announcing Security Design Review
HIGH 7.4 Go

Harbor fails to validate the user permissions when updating p2p preheat policies

GHSA-r864-28pw-8682 · BIT-harbor-2022-31668 · CVE-2022-31668 · GHSA-3wpx-625q-22j7 · GO-2024-3268

Published · Modified

Description

Harbor fails to validate the user permissions when updating p2p preheat policies. By sending a request to update a p2p preheat policy with an id that belongs to a project that the currently authenticated user doesn't have access to, the attacker could modify p2p preheat policies configured in other projects.

Ready to move

Start Securing

Free, no credit card | First findings in minutes