CVE-2019-3990

A User Enumeration flaw exists in Harbor. The issue is present in the "/users" API endpoint. This endpoint is supposed to be restricted to administrators. This restriction is able to be bypassed and information can be obtained about registered users can be obtained via the "search" functionality.
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

OR cpe:2.3:a:linuxfoundation:harbor:*:*:*:*:*:*:*:*
cpe:2.3:a:linuxfoundation:harbor:*:*:*:*:*:*:*:*
cpe:2.3:a:linuxfoundation:harbor:1.9.0:-:*:*:*:*:*:*
cpe:2.3:a:linuxfoundation:harbor:1.9.0:rc1:*:*:*:*:*:*
cpe:2.3:a:linuxfoundation:harbor:1.9.0:rc2:*:*:*:*:*:*
cpe:2.3:a:linuxfoundation:harbor:1.9.1:-:*:*:*:*:*:*
cpe:2.3:a:linuxfoundation:harbor:1.9.1:rc1:*:*:*:*:*:*

Information

Published : 2019-12-03 09:15

Updated : 2020-08-24 10:37


NVD link : CVE-2019-3990

Mitre link : CVE-2019-3990


JSON object : View

CWE
CWE-269

Improper Privilege Management

Advertisement

dedicated server usa

Products Affected

linuxfoundation

  • harbor