CVE-2019-16097
MEDIUM6.5EPSS 93.6%Missing Authorization in Harbor in github.com/goharbor/harbor
Published: 2/15/2022Modified: 3/3/2026
Description
Missing Authorization in Harbor in github.com/goharbor/harbor
Affected packages (2)
- Go/github.com/goharbor/harbor>= 1.7.0, < 1.9.0-rc1
- Go/github.com/goharbor/harbor>= 1.7.0, < 1.9.0-rc1
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM6.5 | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N |
References (9)
- ADVISORYhttps://github.com/advisories/GHSA-9wvh-ff5f-xjpj
- ADVISORYhttps://nvd.nist.gov/vuln/detail/CVE-2019-16097
- WEBhttps://github.com/goharbor/harbor/commit/b6db8a8a106259ec9a2c48be8a380cb3b37cf517
- WEBhttps://github.com/goharbor/harbor/compare/v1.8.2...v1.9.0-rc1
- WEBhttps://github.com/goharbor/harbor/releases/tag/v1.7.6
- WEBhttps://github.com/goharbor/harbor/releases/tag/v1.8.3
- WEBhttps://github.com/ianxtianxt/CVE-2019-16097
- WEBhttps://unit42.paloaltonetworks.com/critical-vulnerability-in-harbor-enables-privilege-escalation-from-zero-to-admin-cve-2019-16097
- WEBhttp://www.vmware.com/security/advisories/VMSA-2019-0015.html