CVE-2017-17697

The Ping() function in ui/api/target.go in Harbor through 1.3.0-rc4 has SSRF via the endpoint parameter to /api/targets/ping.
References
Link Resource
https://github.com/vmware/harbor/issues/3755 Exploit Third Party Advisory
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

OR cpe:2.3:a:linuxfoundation:harbor:1.3.0:rc1:*:*:*:*:*:*
cpe:2.3:a:linuxfoundation:harbor:1.3.0:rc3:*:*:*:*:*:*
cpe:2.3:a:linuxfoundation:harbor:*:*:*:*:*:*:*:*
cpe:2.3:a:linuxfoundation:harbor:1.3.0:-:*:*:*:*:*:*
cpe:2.3:a:linuxfoundation:harbor:1.3.0:rc2:*:*:*:*:*:*
cpe:2.3:a:linuxfoundation:harbor:1.3.0:rc4:*:*:*:*:*:*

Information

Published : 2017-12-15 01:29

Updated : 2020-04-01 08:03


NVD link : CVE-2017-17697

Mitre link : CVE-2017-17697


JSON object : View

CWE
CWE-918

Server-Side Request Forgery (SSRF)

Advertisement

dedicated server usa

Products Affected

linuxfoundation

  • harbor