CVE-2019-3990

A User Enumeration flaw exists in Harbor. The issue is present in the "/users" API endpoint. This endpoint is supposed to be restricted to administrators. This restriction is able to be bypassed and information can be obtained about registered users can be obtained via the "search" functionality.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:linuxfoundation:harbor:*:*:*:*:*:*:*:*
cpe:2.3:a:linuxfoundation:harbor:*:*:*:*:*:*:*:*
cpe:2.3:a:linuxfoundation:harbor:1.9.0:-:*:*:*:*:*:*
cpe:2.3:a:linuxfoundation:harbor:1.9.0:rc1:*:*:*:*:*:*
cpe:2.3:a:linuxfoundation:harbor:1.9.0:rc2:*:*:*:*:*:*
cpe:2.3:a:linuxfoundation:harbor:1.9.1:-:*:*:*:*:*:*
cpe:2.3:a:linuxfoundation:harbor:1.9.1:rc1:*:*:*:*:*:*

History

21 Nov 2024, 04:43

Type Values Removed Values Added
References () https://github.com/goharbor/harbor/security/advisories/GHSA-6qj9-33j4-rvhg - Patch, Third Party Advisory () https://github.com/goharbor/harbor/security/advisories/GHSA-6qj9-33j4-rvhg - Patch, Third Party Advisory
References () https://www.tenable.com/security/research/tra-2019-50 - Third Party Advisory () https://www.tenable.com/security/research/tra-2019-50 - Third Party Advisory

Information

Published : 2019-12-03 17:15

Updated : 2024-11-21 04:43


NVD link : CVE-2019-3990

Mitre link : CVE-2019-3990

CVE.ORG link : CVE-2019-3990


JSON object : View

Products Affected

linuxfoundation

  • harbor
CWE
CWE-269

Improper Privilege Management