BIT-harbor-2022-31666
Dashboard / Vulnerabilities / BIT-harbor-2022-31666
BIT-harbor-2022-31666
Published: 26 Jan 2026Last Modified: 10 Sept 2026
Summary: Harbor fails to validate user permissions while Viewing, updating and deleting Webhook policies
Details: Harbor fails to validate user permissions while deleting Webhook policies, allowing malicious users to view, update and delete Webhook policies of other users. The attacker could modify Webhook policies configured in other projects.
References: https://github.com/goharbor/harbor/security/advisories/GHSA-8hwq-5f22-jfr3, https://nvd.nist.gov/vuln/detail/CVE-2022-31666
Affected packages
Package
Name: harbor
Purl: pkg:bitnami/harbor
Affected ranges
Type: SEMVER
Events:
Introduced- 2.0.0
Fixed -2.4.3
Affected versions
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
