Vulnerabilities
Vulnerable Software
Linuxfoundation:  Security Vulnerabilities
Harbor fails to validate the user permissions when updating a robot account that belongs to a project that the authenticated user doesn’t have access to.  By sending a request that attempts to update a robot account, and specifying a robot account id and robot account name that belongs to a different project that the user doesn’t have access to, it was possible to revoke the robot account permissions.
CVSS Score
6.4
EPSS Score
0.001
Published
2024-11-14
Harbor fails to validate the user permissions when updating p2p preheat policies. By sending a request to update a p2p preheat policy with an id that belongs to a project that the currently authenticated user doesn't have access to, the attacker could modify p2p preheat policies configured in other projects.
CVSS Score
7.4
EPSS Score
0.001
Published
2024-11-14
Harbor fails to validate the user permissions when updating tag immutability policies.  By sending a request to update a tag immutability policy with an id that belongs to a project that the currently authenticated user doesn’t have access to, the attacker could modify tag immutability policies configured in other projects.
CVSS Score
6.4
EPSS Score
0.001
Published
2024-11-14
In da, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09124360; Issue ID: MSV-1823.
CVSS Score
6.2
EPSS Score
0.0
Published
2024-11-04
In da, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS09073261; Issue ID: MSV-1772.
CVSS Score
8.4
EPSS Score
0.0
Published
2024-11-04
In PyTorch <=2.4.1, the RemoteModule has Deserialization RCE. NOTE: this is disputed by multiple parties because this is intended behavior in PyTorch distributed computing.
CVSS Score
9.8
EPSS Score
0.131
Published
2024-10-29
The health endpoint is public so everybody can see a list of all services. It is potentially valuable information for attackers.
CVSS Score
9.0
EPSS Score
0.001
Published
2024-10-10
The conformance validation endpoint is public so everybody can verify the conformance of onboarded services. The response could contain specific information about the service, including available endpoints, and swagger. It could advise about the running version of a service to an attacker. The attacker could also check if a service is running.
CVSS Score
5.3
EPSS Score
0.001
Published
2024-10-10
In power, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08996886; Issue ID: MSV-1626.
CVSS Score
6.7
EPSS Score
0.0
Published
2024-10-07
In power, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08997492; Issue ID: MSV-1625.
CVSS Score
6.7
EPSS Score
0.0
Published
2024-10-07


Contact Us

Shodan ® - All rights reserved