Description
A timing condition in Harbor 2.6.x and below, Harbor 2.7.2 and below, Harbor 2.8.2 and below, and Harbor 1.10.17 and below allows an attacker with network access to
create jobs/stop job tasks and retrieve job task information.
create jobs/stop job tasks and retrieve job task information.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-2779 | A timing condition in Harbor 2.6.x and below, Harbor 2.7.2 and below, Harbor 2.8.2 and below, and Harbor 1.10.17 and below allows an attacker with network access to create jobs/stop job tasks and retrieve job task information. |
Github GHSA |
GHSA-mq6f-5xh5-hgcf | Harbor timing attack risk |
References
History
No history.
Status: PUBLISHED
Assigner: vmware
Published:
Updated: 2024-09-04T13:18:17.730Z
Reserved: 2022-11-01T15:41:50.396Z
Link: CVE-2023-20902
Updated: 2024-08-02T09:21:33.417Z
Status : Modified
Published: 2023-11-09T01:15:07.660
Modified: 2024-11-21T07:41:47.283
Link: CVE-2023-20902
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA