CVE-2019-19026: SQL Injection
Published Mar 20, 2020
·Updated
Cloud Native Computing Foundation Harbor prior to 1.8.6 and 1.9.3 allows SQL Injection via project quotas in the VMware Harbor Container Registry for the Pivotal Platform.
Affected Software
3 affected components
linuxfoundation Harbor>=1.7.0<1.8.6
linuxfoundation Harbor>=1.9.0<1.9.3
Pivotal Vmware Harbor Registry
Event History
Mar 20, 2020
CVE Published
via MITRE·02:01 AM
Data Sourced
via MITRE·02:01 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this security issue in Harbor?
The vulnerability ID for this security issue in Harbor is CVE-2019-19026.
2
What is the severity of CVE-2019-19026?
The severity of CVE-2019-19026 is medium (4.9).
3
How does CVE-2019-19026 affect the Cloud Native Computing Foundation Harbor?
CVE-2019-19026 affects the Cloud Native Computing Foundation Harbor versions prior to 1.8.6 and 1.9.3.
4
How can SQL Injection be exploited in VMware Harbor Container Registry for the Pivotal Platform?
SQL Injection can be exploited in VMware Harbor Container Registry for the Pivotal Platform via project quotas.
5
Is there a fix available for CVE-2019-19026?
Yes, the fix for CVE-2019-19026 is available in Harbor versions 1.8.6 and 1.9.3.