CVE-2022-31668
CVSS 3.1 Score 7.4 of 10 (high)
Details
Published Nov 14, 2024
Updated: Nov 15, 2024
CWE ID 285
Summary
CVE-2022-31668 is a vulnerability affecting Harbor, an open-source container registry. This issue arises from Harbor's failure to validate user permissions when updating p2p preheat policies. An attacker can exploit this flaw by making a request to modify a p2p preheat policy with an ID belonging to a project the attacker doesn't have access to. Successful exploitation allows the attacker to manipulate p2p preheat policies configured in different projects, potentially impacting their functionality or security.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.