CVE-2022-31666

Harbor fails to validate user permissions while deleting Webhook policies, allowing malicious users to view, update and delete Webhook policies of other users.  The attacker could modify Webhook policies configured in other projects.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:linuxfoundation:harbor:*:*:*:*:*:*:*:*
cpe:2.3:a:linuxfoundation:harbor:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2024-11-14 12:15

Updated : 2025-02-28 22:15


NVD link : CVE-2022-31666

Mitre link : CVE-2022-31666

CVE.ORG link : CVE-2022-31666


JSON object : View

Products Affected

linuxfoundation

  • harbor
CWE
CWE-285

Improper Authorization

CWE-862

Missing Authorization