First published: Thu Jan 12 2023(Updated: )
** DISPUTED ** An access control issue in Harbor v1.X.X to v2.5.3 allows attackers to access public and private image repositories without authentication. NOTE: the vendor's position is that this "is clearly described in the documentation as a feature."
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Harbor | >=1.1.0<=2.5.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this access control issue in Harbor is CVE-2022-46463.
The severity of CVE-2022-46463 is high with a severity value of 7.5.
The software versions affected by CVE-2022-46463 are Harbor v1.X.X to v2.5.3.
Attackers can exploit CVE-2022-46463 by accessing public and private image repositories in Harbor without authentication.
The vendor's position on CVE-2022-46463 is that it is described as a feature in the documentation.