CVE-2022-31671

CVSS 3.1 Score 7.4 of 10 (high)

Details

Published Nov 14, 2024
Updated: Nov 15, 2024
CWE ID 285

Summary

CVE-2022-31671 is a vulnerability affecting Harbor, an open-source container registry. Malicious authenticated users can exploit this issue by sending requests to read or update P2P preheat execution logs with different job IDs. Despite the intended job ID, Harbor fails to validate user permissions, enabling attackers to access all job logs stored in the Harbor database, potentially compromising sensitive information.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share