CVE-2023-20902

Severity CVSS v4.0:
Pending analysis
Type:
CWE-362 Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
Publication date:
09/11/2023
Last modified:
16/11/2023

Description

A timing condition in Harbor 2.6.x and below, Harbor 2.7.2 and below,  Harbor 2.8.2 and below, and Harbor 1.10.17 and below allows an attacker with network access to <br /> create jobs/stop job tasks and retrieve job task information.<br /> <br /> <br />

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:linuxfoundation:harbor:*:*:*:*:*:*:*:* 1.10.17 (excluding)
cpe:2.3:a:linuxfoundation:harbor:*:*:*:*:*:*:*:* 2.6.0 (including) 2.6.4 (including)
cpe:2.3:a:linuxfoundation:harbor:*:*:*:*:*:*:*:* 2.7.0 (including) 2.7.3 (excluding)
cpe:2.3:a:linuxfoundation:harbor:*:*:*:*:*:*:*:* 2.8.0 (including) 2.8.3 (excluding)