First published: Tue Dec 03 2019(Updated: )
A User Enumeration flaw exists in Harbor. The issue is present in the "/users" API endpoint. This endpoint is supposed to be restricted to administrators. This restriction is able to be bypassed and information can be obtained about registered users can be obtained via the "search" functionality.
Credit: vulnreport@tenable.com
Affected Software | Affected Version | How to fix |
---|---|---|
Linuxfoundation Harbor | >=1.7.0<=1.7.6 | |
Linuxfoundation Harbor | >=1.8.0<=1.8.5 | |
Linuxfoundation Harbor | =1.9.0 | |
Linuxfoundation Harbor | =1.9.0-rc1 | |
Linuxfoundation Harbor | =1.9.0-rc2 | |
Linuxfoundation Harbor | =1.9.1 | |
Linuxfoundation Harbor | =1.9.1-rc1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-3990 is a User Enumeration flaw in Harbor, specifically in the /users API endpoint.
CVE-2019-3990 allows unauthorized users to obtain information about registered users via the "search" functionality.
CVE-2019-3990 has a severity level of medium (4.3).
Harbor versions 1.7.0 to 1.7.6, 1.8.0 to 1.8.5, and 1.9.0 (including RC1 and RC2) are affected by CVE-2019-3990.
To fix CVE-2019-3990, upgrade to a version of Harbor that is not affected by this vulnerability.