CVE-2019-3990

A User Enumeration flaw exists in Harbor. The issue is present in the "/users" API endpoint. This endpoint is supposed to be restricted to administrators. This restriction is able to be bypassed and information can be obtained about registered users can be obtained via the "search" functionality.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:linuxfoundation:harbor:*:*:*:*:*:*:*:*
cpe:2.3:a:linuxfoundation:harbor:*:*:*:*:*:*:*:*
cpe:2.3:a:linuxfoundation:harbor:1.9.0:-:*:*:*:*:*:*
cpe:2.3:a:linuxfoundation:harbor:1.9.0:rc1:*:*:*:*:*:*
cpe:2.3:a:linuxfoundation:harbor:1.9.0:rc2:*:*:*:*:*:*
cpe:2.3:a:linuxfoundation:harbor:1.9.1:-:*:*:*:*:*:*
cpe:2.3:a:linuxfoundation:harbor:1.9.1:rc1:*:*:*:*:*:*

History

No history.

Information

Published : 2019-12-03 17:15

Updated : 2024-02-04 20:39


NVD link : CVE-2019-3990

Mitre link : CVE-2019-3990

CVE.ORG link : CVE-2019-3990


JSON object : View

Products Affected

linuxfoundation

  • harbor
CWE
CWE-269

Improper Privilege Management