Sploitus

CVE-2022-31667

No indexed exploits for CVE-2022-31667 yet

Harbor fails to validate the user permissions when updating a robot account that belongs to a project that the authenticated user doesn’t have access to.  By sending a request that attempts to update a robot account, and specifying a robot account id and robot account name that belongs to a different project that the user doesn’t have access to, it was possible to revoke the robot account permissions.

Affected products
Harbor
Linuxfoundation Harbor
< 2.4.3, 2.5.2
Fix
Available
CVSS 3.1
6.4 MEDIUM
EPSS
0.5% (40th percentile)
Weakness
CWE-285, CWE-863
NVD status
Analyzed
Published
2024-11-14
CVE-2022-31667 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2022-31667 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2022-31667 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.