CVE-2022-31669
Harbor fails to validate the user permissions when updating tag immutability policies.
By sending a request to update
Harbor fails to validate the user permissions when updating tag immutability policies. By sending a request to update a tag immutability policy with an id that belongs to a project that the currently authenticated user doesn’t have access to, the attacker could modify tag immutability policies configured in other projects.
MEDIUM · CVSS 6.4
EPSS 0.00066
Monitor
- No active-exploitation, high-EPSS, or public-exploit signals - routine patching cadence
Sigma rules0
YARA rules0