CVE-2022-46463
Severity CVSS v4.0:
Pending analysis
Type:
CWE-306
Missing Authentication for Critical Function
Publication date:
13/01/2023
Last modified:
08/04/2025
Description
An access control issue in Harbor v1.X.X to v2.5.3 allows attackers to access public and private image repositories without authentication. NOTE: the vendor's position is that this "is clearly described in the documentation as a feature."
Impact
Base Score 3.x
7.50
Severity 3.x
HIGH
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:a:linuxfoundation:harbor:*:*:*:*:*:*:*:* | 1.1.0 (including) | 2.5.3 (including) |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- https://github.com/Vad1mo
- https://github.com/lanqingaa/123/blob/main/README.md
- https://github.com/lanqingaa/123/tree/bb48caa844d88b0e41e69157f2a2734311abf02d
- https://github.com/Vad1mo
- https://github.com/lanqingaa/123/blob/main/README.md
- https://github.com/lanqingaa/123/tree/bb48caa844d88b0e41e69157f2a2734311abf02d