GHSA-9wvh-ff5f-xjpj
Dashboard / Vulnerabilities / GHSA-9wvh-ff5f-xjpj
GHSA-9wvh-ff5f-xjpj
Summary: Missing Authorization in Harbor
Details: core/api/user.go in Harbor 1.7.0 through 1.8.2 allows non-admin users to create admin accounts via the POST /api/users API. This is fixed in 1.9.0-rc1.
References: https://nvd.nist.gov/vuln/detail/CVE-2019-16097, https://github.com/goharbor/harbor/commit/b6db8a8a106259ec9a2c48be8a380cb3b37cf517, https://github.com/goharbor/harbor/compare/v1.8.2...v1.9.0-rc1, https://github.com/goharbor/harbor/releases/tag/v1.7.6, https://github.com/goharbor/harbor/releases/tag/v1.8.3, https://github.com/ianxtianxt/CVE-2019-16097, https://unit42.paloaltonetworks.com/critical-vulnerability-in-harbor-enables-privilege-escalation-from-zero-to-admin-cve-2019-16097, http://www.vmware.com/security/advisories/VMSA-2019-0015.html
Affected packages
Package
Name: github.com/goharbor/harbor
Purl: pkg:golang/github.com/goharbor/harbor
Affected ranges
Type: SEMVER
Events:
