CVE-2019-19026 – github.com/goharbor/harbor
Package
Manager: go
Name: github.com/goharbor/harbor
Vulnerable Version: >=1.7.0 <1.8.6 || >=1.9.0 <1.9.3
Severity
Level: Medium
CVSS v3.1: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
EPSS: 0.00571 pctl0.6766
Details
SQL Injection in Cloud Native Computing Foundation Harbor Cloud Native Computing Foundation Harbor prior to 1.8.6 and 1.9.3 allows SQL Injection via project quotas in the VMware Harbor Container Registry for the Pivotal Platform.
Metadata
Created: 2021-05-18T18:27:43Z
Modified: 2021-05-04T22:00:55Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/05/GHSA-w4x5-jqq4-qc8x/GHSA-w4x5-jqq4-qc8x.json
CWE IDs: ["CWE-89"]
Alternative ID: GHSA-w4x5-jqq4-qc8x
Finding: F106
Auto approve: 1