CVE-2022-31666

Harbor fails to validate user permissions while deleting Webhook policies, allowing malicious users to view, update and delete Webhook policies of other users.  The attacker could modify Webhook policies configured in other projects.
Configurations

No configuration.

History

No history.

Information

Published : 2024-11-14 12:15

Updated : 2024-11-15 13:58


NVD link : CVE-2022-31666

Mitre link : CVE-2022-31666

CVE.ORG link : CVE-2022-31666


JSON object : View

Products Affected

No product.

CWE
CWE-285

Improper Authorization