CVE-2017-17697: SSRF
Published Dec 15, 2017
·Updated
The Ping() function in ui/api/target.go in Harbor through 1.3.0-rc4 has SSRF via the endpoint parameter to /api/targets/ping.
Affected Software
6 affected components
linuxfoundation Harbor<1.3.0
linuxfoundation Harbor=1.3.0
linuxfoundation Harbor=1.3.0-rc1
linuxfoundation Harbor=1.3.0-rc2
linuxfoundation Harbor=1.3.0-rc3
linuxfoundation Harbor=1.3.0-rc4
Event History
Dec 15, 2017
CVE Published
via MITRE·09:00 AM
Data Sourced
via MITRE·09:00 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2017-17697.
2
What is the severity of CVE-2017-17697?
The severity of CVE-2017-17697 is high.
3
What is the affected software?
The affected software is Linuxfoundation Harbor versions up to 1.3.0 and 1.3.0-rc1 through 1.3.0-rc4.
4
What is the vulnerability description?
The Ping() function in ui/api/target.go in Harbor through 1.3.0-rc4 has SSRF via the endpoint parameter to /api/targets/ping.
5
Is there a fix available for CVE-2017-17697?
Yes, a fix is available. Please refer to the provided reference link for more information.