CVE-2020-13788

Severity CVSS v4.0:
Pending analysis
Type:
CWE-918 Server-Side Request Forgery (SSRF)
Publication date:
15/07/2020
Last modified:
22/07/2020

Description

Harbor prior to 2.0.1 allows SSRF with this limitation: an attacker with the ability to edit projects can scan ports of hosts accessible on the Harbor server's intranet.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:linuxfoundation:harbor:*:*:*:*:*:*:*:* 2.0.1 (excluding)