CVE-2020-29662: Medium severity harbor vulnerability
Published Feb 2, 2021
·Updated
In Harbor 2.0 before 2.0.5 and 2.1.x before 2.1.2 the catalog’s registry API is exposed on an unauthenticated path.
Affected Software
2 affected components
linuxfoundation Harbor>=2.0<2.0.5
linuxfoundation Harbor>=2.1.0<2.1.2
Event History
Feb 2, 2021
CVE Published
via MITRE·08:54 PM
Data Sourced
via MITRE·08:54 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2020-29662?
The severity of CVE-2020-29662 is medium with a CVSS score of 5.3.
2
How does CVE-2020-29662 affect Harbor?
CVE-2020-29662 affects Harbor versions 2.0 before 2.0.5 and 2.1.x before 2.1.2 by exposing the catalog's registry API on an unauthenticated path.
3
What is the Common Weakness Enumeration (CWE) ID for CVE-2020-29662?
The Common Weakness Enumeration (CWE) ID for CVE-2020-29662 is CWE-319.
4
How can I fix CVE-2020-29662?
To fix CVE-2020-29662, it is recommended to upgrade Harbor to version 2.0.5 or 2.1.2.
5
Where can I find more information about CVE-2020-29662?
More information about CVE-2020-29662 can be found on the Harbor project's GitHub page: https://github.com/goharbor/harbor/security/advisories/GHSA-38r5-34mr-mvm7.