TROYANOSYVIRUS
Retour aux CVEs

CVE-2019-3990

MEDIUM
4.3

Description

A User Enumeration flaw exists in Harbor. The issue is present in the "/users" API endpoint. This endpoint is supposed to be restricted to administrators. This restriction is able to be bypassed and information can be obtained about registered users can be obtained via the "search" functionality.

Details CVE

Score CVSS v3.14.3
SeveriteMEDIUM
Vecteur CVSSCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Vecteur d'attaqueNETWORK
ComplexiteLOW
Privileges requisLOW
Interaction utilisateurNONE
Publie12/3/2019
Derniere modification11/21/2024
Sourcenvd
Observations honeypot0

Produits affectes

linuxfoundation:harbor

Faiblesses (CWE)

CWE-269

Correlations IOC

Aucune correlation enregistree

This product uses data from the NVD API but is not endorsed or certified by the NVD.