CVE-2022-31671
CVSS 3.1 Score 7.4 of 10 (high)
Details
Published Nov 14, 2024
Updated: Nov 15, 2024
CWE ID 285
Summary
CVE-2022-31671 is a vulnerability affecting Harbor, an open-source container registry. Malicious authenticated users can exploit this issue by sending requests to read or update P2P preheat execution logs with different job IDs. Despite the intended job ID, Harbor fails to validate user permissions, enabling attackers to access all job logs stored in the Harbor database, potentially compromising sensitive information.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.