漏洞描述
Harbor 1.7.0 through 1.8.2 is susceptible to privilege escalation via core/api/user.go, which allows allows non-admin users to create admin accounts via the POST /api/users API when Harbor is setup with DB as an authentication backend and allows user to do self-registration.
影响产品
修复建议
建议关注厂商安全公告,及时升级至已修复版本,并结合实际资产暴露情况采取缓解措施。
参考链接
unit42.paloaltonetworks.comhttps://unit42.paloaltonetworks.com/critical-vulnerability-in-harbor-enables-privilege-escalation-from-zero-to-admin-cve-2019-16097/↗github.comhttps://github.com/goharbor/harbor/issues/8951↗nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2019-16097↗github.comhttps://github.com/goharbor/harbor/commit/b6db8a8a106259ec9a2c48be8a380cb3b37cf517↗www.vmware.comhttp://www.vmware.com/security/advisories/VMSA-2019-0015.html↗