CVE-2019-19030
Cloud Native Computing Foundation Harbor before 1.10.3 and 2.x before 2.0.1 allows resource enumeration because unauthenticated API calls reveal (via the HTTP status code) whether a resource exists.
- Affected products
- Harbor
- Linuxfoundation Harbor
- < 1.10.3, 2.0.1
- Fix
- Available
- CVSS 3.1
- 5.3 MEDIUM
- EPSS
- 1.9% (78th percentile)
- Weakness
- CWE-204
- NVD status
- Modified
- Published
- 2022-12-26
CVE-2019-19030 at NVD
1 known exploit for CVE-2019-19030
Proof-of-concept code and exploit modules indexed by Sploitus