Harbor
Vendor:
First CVE: Dec 15, 2017 · Active for 8 years
23
Total CVEs
More Total CVEs than 95% of tracked products
3.3
Avg CVEs / Year
Higher CVE frequency than 82% of tracked products
6.4
Avg CVSS
Higher Avg CVSS than 28% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Harbor over time
Volume of CVEsAvg CVSS Base Score
First CVE
Dec 15, 2017
8 years ago
Most Recent CVE
Nov 14, 2024
617 days ago
CVE Severity & Scoring
Harbor23 CVEs
57%
43%
All CVEs352,231 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network23 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low22 (95.7%)
High1 (4.3%)
Unknown0 (0.0%)
User Interaction
None21 (91.3%)
Unknown0 (0.0%)
Required2 (8.7%)
Privileges Required
Low12 (52.2%)
High3 (13.0%)
None8 (34.8%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (23 CVEs).
23 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-16097MEDIUM core/api/user.go in Harbor 1.7.0 through 1.8.2 allows non-admin users to create admin accounts via the POST /api/users API, when Harbor is setup with DB as authentication backend a | Sep 8, 2019 | 6.5 | 46 | NO | YES |
CVE-2022-46463HIGH An access control issue in Harbor v1.X.X to v2.5.3 allows attackers to access public and private image repositories without authentication. NOTE: the vendor's position is that this | Jan 13, 2023 | 7.5 | 28 | NO | NO |
CVE-2019-19023HIGH Cloud Native Computing Foundation Harbor prior to 1.8.6 and 1.9.3 has a Privilege Escalation Vulnerability in the VMware Harbor Container Registry for the Pivotal Platform. | Mar 20, 2020 | 8.8 | 28 | NO | NO |
CVE-2019-19025HIGH Cloud Native Computing Foundation Harbor prior to 1.8.6 and 1.9.3 allows CSRF in the VMware Harbor Container Registry for the Pivotal Platform. | Mar 20, 2020 | 8.8 | 27 | NO | NO |
CVE-2017-17697HIGH The Ping() function in ui/api/target.go in Harbor through 1.3.0-rc4 has SSRF via the endpoint parameter to /api/targets/ping. | Dec 15, 2017 | 8.6 | 27 | NO | NO |
CVE-2019-19029HIGH Cloud Native Computing Foundation Harbor prior to 1.8.6 and 1.9.3 allows SQL Injection via user-groups in the VMware Harbor Container Registry for the Pivotal Platform. | Mar 20, 2020 | 7.2 | 24 | NO | NO |
CVE-2019-16919HIGH Harbor API has a Broken Access Control vulnerability. The vulnerability allows project administrators to use the Harbor API to create a robot account with unauthorized push and/or | Oct 18, 2019 | 7.5 | 24 | NO | NO |
CVE-2022-31671HIGH Harbor fails to validate user permissions when reading and updating job execution logs through the P2P preheat execution logs. By sending a request that attempts to read/update P2P | Nov 14, 2024 | 7.4 | 22 | NO | NO |
CVE-2022-31670HIGH Harbor fails to validate the user permissions when updating tag retention policies.
By sending a request to update a tag retention policy with an id that belongs to a project tha | Nov 14, 2024 | 7.7 | 22 | NO | NO |
CVE-2022-31669HIGH Harbor fails to validate the user permissions when updating tag immutability policies.
By sending a request to update a tag immutability policy with an id that belongs to a
proje | Nov 14, 2024 | 7.7 | 21 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (23 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
4.3% of CVEs· 97th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (23 CVEs).
Media Mentions
Signals from CVEs in this product scope (23 CVEs).
Top CNAs Publishing CVEs For Harbor
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 2.10.0 | 1 | 6.1 | 0.4% | 0 | 0 |
| 1.9.1 | 1 | 4.3 | 1.0% | 0 | 0 |
| 1.9.0 | 3 | 5.4 | 5.6% | 0 | 1 |
| 1.8.2 | 1 | 6.5 | 23.3% | 0 | 1 |
| 1.8.1 | 1 | 6.5 | 23.3% | 0 | 1 |
| 1.8.0 | 1 | 6.5 | 23.3% | 0 | 1 |
| 1.7.5 | 1 | 6.5 | 23.3% | 0 | 1 |
| 1.7.4 | 1 | 6.5 | 23.3% | 0 | 1 |
| 1.7.3 | 1 | 6.5 | 23.3% | 0 | 1 |
| 1.7.2 | 1 | 6.5 | 23.3% | 0 | 1 |
| 1.7.1 | 1 | 6.5 | 23.3% | 0 | 1 |
| 1.7.0 | 1 | 6.5 | 23.3% | 0 | 1 |
| 1.3.0 | 1 | 8.6 | 1.4% | 0 | 0 |