CVE-2019-16097 is a critical privilege escalation vulnerability affecting Harbor versions 1.7.0 through 1.8.2. It allows authenticated non-admin users to create new administrator accounts by exploiting the POST /api/users API when Harbor is configured with a DB authentication backend and self-registration is enabled. The vulnerability has a CVSS score of 6.5 (Medium) due to its low attack complexity and high impact on integrity, enabling unauthorized administrative access. While not listed on the KEV catalog, its high EPSS score and multiple Nuclei templates indicate a significant likelihood of exploitation, further supported by extensive media coverage and community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.7.0CPE matchmatch criteria | cpe:2.3:a:linuxfoundation:harbor:1.7.0:-:*:*:*:*:*:* | ||
1.7.0CPE matchmatch criteria | cpe:2.3:a:linuxfoundation:harbor:1.7.0:rc1:*:*:*:*:*:* | ||
1.7.0CPE matchmatch criteria | cpe:2.3:a:linuxfoundation:harbor:1.7.0:rc2:*:*:*:*:*:* | ||
1.7.1CPE matchmatch criteria | cpe:2.3:a:linuxfoundation:harbor:1.7.1:*:*:*:*:*:*:* | ||
1.7.2CPE matchmatch criteria | cpe:2.3:a:linuxfoundation:harbor:1.7.2:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.