CVE-2022-31666
Harbor fails to validate user permissions while deleting Webhook policies, allowing malicious users to view, update and delete Webhook policies of other users.  The attacker could modify Webhook policies configured in other projects.
- Affected products
- Harbor
- Linuxfoundation Harbor
- < 2.4.3, 2.5.2
- Fix
- Available
- CVSS 3.1
- 7.7 HIGH
- EPSS
- 0.5% (40th percentile)
- Weakness
- CWE-285, CWE-862
- NVD status
- Analyzed
- Published
- 2024-11-14
CVE-2022-31666 at NVD
No indexed exploits for CVE-2022-31666 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2022-31666 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.