CVE-2022-31668: User permission validation failure and disclosure of P2P preheat execution logs
Harbor fails to validate the user permissions when updating p2p preheat policies. By sending a request to update a p2p preheat policy with an id that belongs to a project that the currently authenticated user doesn't have access to, the attacker could modify p2p preheat policies configured in other projects.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-31668?
CVE-2022-31668 is a critical vulnerability that allows unauthorized modification of p2p preheat policies.
How do I fix CVE-2022-31668?
To fix CVE-2022-31668, upgrade to a version of Harbor that is greater than 2.5.2 or apply the recommended patches.
What versions are affected by CVE-2022-31668?
CVE-2022-31668 affects Harbor versions prior to 2.4.3 and 2.5.2.
What type of vulnerability is CVE-2022-31668?
CVE-2022-31668 is an access control vulnerability that fails to validate user permissions.
Who can exploit CVE-2022-31668?
An attacker with access to update p2p preheat policies can exploit CVE-2022-31668 if they target projects they shouldn't have access to.