Harbor

Vendor:

First CVE: Dec 15, 2017 · Active for 8 years

23
Total CVEs
More Total CVEs than 95% of tracked products
3.3
Avg CVEs / Year
Higher CVE frequency than 82% of tracked products
6.4
Avg CVSS
Higher Avg CVSS than 28% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Harbor over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 15, 2017
8 years ago
Most Recent CVE
Nov 14, 2024
617 days ago

CVE Severity & Scoring

Harbor23 CVEs
All CVEs352,231 CVEs
MediumHigh
Attack Vector
Local0 (0.0%)
Network23 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low22 (95.7%)
High1 (4.3%)
Unknown0 (0.0%)
User Interaction
None21 (91.3%)
Unknown0 (0.0%)
Required2 (8.7%)
Privileges Required
Low12 (52.2%)
High3 (13.0%)
None8 (34.8%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (23 CVEs).

23 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
core/api/user.go in Harbor 1.7.0 through 1.8.2 allows non-admin users to create admin accounts via the POST /api/users API, when Harbor is setup with DB as authentication backend a
Sep 8, 20196.546NOYES
An access control issue in Harbor v1.X.X to v2.5.3 allows attackers to access public and private image repositories without authentication. NOTE: the vendor's position is that this
Jan 13, 20237.528NONO
Cloud Native Computing Foundation Harbor prior to 1.8.6 and 1.9.3 has a Privilege Escalation Vulnerability in the VMware Harbor Container Registry for the Pivotal Platform.
Mar 20, 20208.828NONO
Cloud Native Computing Foundation Harbor prior to 1.8.6 and 1.9.3 allows CSRF in the VMware Harbor Container Registry for the Pivotal Platform.
Mar 20, 20208.827NONO
The Ping() function in ui/api/target.go in Harbor through 1.3.0-rc4 has SSRF via the endpoint parameter to /api/targets/ping.
Dec 15, 20178.627NONO
Cloud Native Computing Foundation Harbor prior to 1.8.6 and 1.9.3 allows SQL Injection via user-groups in the VMware Harbor Container Registry for the Pivotal Platform.
Mar 20, 20207.224NONO
Harbor API has a Broken Access Control vulnerability. The vulnerability allows project administrators to use the Harbor API to create a robot account with unauthorized push and/or
Oct 18, 20197.524NONO
Harbor fails to validate user permissions when reading and updating job execution logs through the P2P preheat execution logs. By sending a request that attempts to read/update P2P
Nov 14, 20247.422NONO
Harbor fails to validate the user permissions when updating tag retention policies.  By sending a request to update a tag retention policy with an id that belongs to a project tha
Nov 14, 20247.722NONO
Harbor fails to validate the user permissions when updating tag immutability policies.  By sending a request to update a tag immutability policy with an id that belongs to a proje
Nov 14, 20247.721NONO

Exploit Exposure

Signals from CVEs in this product scope (23 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
4.3% of CVEs· 97th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (23 CVEs).

Media Mentions

Signals from CVEs in this product scope (23 CVEs).

Top CNAs Publishing CVEs For Harbor

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
2.10.016.10.4%00
1.9.114.31.0%00
1.9.035.45.6%01
1.8.216.523.3%01
1.8.116.523.3%01
1.8.016.523.3%01
1.7.516.523.3%01
1.7.416.523.3%01
1.7.316.523.3%01
1.7.216.523.3%01
1.7.116.523.3%01
1.7.016.523.3%01
1.3.018.61.4%00