Vulnerability Details CVE-2017-17697
The Ping() function in ui/api/target.go in Harbor through 1.3.0-rc4 has SSRF via the endpoint parameter to /api/targets/ping.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 50.7%
CVSS Severity
CVSS v3 Score 8.6
CVSS v2 Score 5.0
Products affected by CVE-2017-17697
-
cpe:2.3:a:linuxfoundation:harbor:0.1.0
-
cpe:2.3:a:linuxfoundation:harbor:0.1.1
-
cpe:2.3:a:linuxfoundation:harbor:0.3.0
-
cpe:2.3:a:linuxfoundation:harbor:0.3.5
-
cpe:2.3:a:linuxfoundation:harbor:0.4.0
-
cpe:2.3:a:linuxfoundation:harbor:0.4.1
-
cpe:2.3:a:linuxfoundation:harbor:0.4.5
-
cpe:2.3:a:linuxfoundation:harbor:0.5.0
-
cpe:2.3:a:linuxfoundation:harbor:1.0.0
-
cpe:2.3:a:linuxfoundation:harbor:1.1.0
-
cpe:2.3:a:linuxfoundation:harbor:1.1.1
-
cpe:2.3:a:linuxfoundation:harbor:1.1.2
-
cpe:2.3:a:linuxfoundation:harbor:1.2.0
-
cpe:2.3:a:linuxfoundation:harbor:1.2.2
-
cpe:2.3:a:linuxfoundation:harbor:1.3.0