CVE-2022-46463

Severity CVSS v4.0:
Pending analysis
Type:
CWE-306 Missing Authentication for Critical Function
Publication date:
13/01/2023
Last modified:
08/04/2025

Description

An access control issue in Harbor v1.X.X to v2.5.3 allows attackers to access public and private image repositories without authentication. NOTE: the vendor's position is that this "is clearly described in the documentation as a feature."

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:linuxfoundation:harbor:*:*:*:*:*:*:*:* 1.1.0 (including) 2.5.3 (including)