CVE-2022-31666

HIGH7.7EPSS 0.13%

Harbor fails to validate user permissions while Viewing, updating and deleting Webhook policies

發布日:2022/9/16修改日:2026/1/26

描述

Harbor fails to validate user permissions while deleting Webhook policies, allowing malicious users to view, update and delete Webhook policies of other users.  The attacker could modify Webhook policies configured in other projects.

受影響套件(2)

CVSS 分數

來源版本嚴重程度向量
osvCVSS 3.1HIGH7.7CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N

參考連結(4)