logo

CVE-2019-19026 github.com/goharbor/harbor

Package

Manager: go
Name: github.com/goharbor/harbor
Vulnerable Version: >=1.7.0 <1.8.6 || >=1.9.0 <1.9.3

Severity

Level: Medium

CVSS v3.1: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N

CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N

EPSS: 0.00571 pctl0.6766

Details

SQL Injection in Cloud Native Computing Foundation Harbor Cloud Native Computing Foundation Harbor prior to 1.8.6 and 1.9.3 allows SQL Injection via project quotas in the VMware Harbor Container Registry for the Pivotal Platform.

Metadata

Created: 2021-05-18T18:27:43Z
Modified: 2021-05-04T22:00:55Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/05/GHSA-w4x5-jqq4-qc8x/GHSA-w4x5-jqq4-qc8x.json
CWE IDs: ["CWE-89"]
Alternative ID: GHSA-w4x5-jqq4-qc8x
Finding: F106
Auto approve: 1