CVE-2019-3990: Medium severity harbor vulnerability
A User Enumeration flaw exists in Harbor. The issue is present in the "/users" API endpoint. This endpoint is supposed to be restricted to administrators. This restriction is able to be bypassed and information can be obtained about registered users can be obtained via the "search" functionality.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2019-3990?
CVE-2019-3990 is a User Enumeration flaw in Harbor, specifically in the /users API endpoint.
How does CVE-2019-3990 affect Harbor?
CVE-2019-3990 allows unauthorized users to obtain information about registered users via the "search" functionality.
What is the severity of CVE-2019-3990?
CVE-2019-3990 has a severity level of medium (4.3).
Which versions of Harbor are affected by CVE-2019-3990?
Harbor versions 1.7.0 to 1.7.6, 1.8.0 to 1.8.5, and 1.9.0 (including RC1 and RC2) are affected by CVE-2019-3990.
How can I fix CVE-2019-3990 in Harbor?
To fix CVE-2019-3990, upgrade to a version of Harbor that is not affected by this vulnerability.