Harbor Container Registry Vulnerability: Update Now or Risk Catastrophic Data Exposure!

Unit 42 researchers discovered a broken object-level authorization (BOLA) vulnerability in Harbor versions before 2.9.5, tracked as CVE-2024-22278. This flaw allows users with Maintainer roles to perform unauthorized actions. Organizations should update to the latest Harbor versions to mitigate risks associated with this BOLA vulnerability.

Hot Take:

Looks like Harbor has a new worm on its container! This BOLA vulnerability is no joke, unless you find the idea of rogue Maintainers having a field day with your project settings hilarious. Time to patch up before your containers start spilling secrets like an overstuffed piñata!

Key Points:

  • Unit 42 discovered a BOLA vulnerability in Harbor versions before 2.9.5.
  • Vulnerability tracked as CVE-2024-22278 with a CVSS score of 6.4.
  • Exploited by Maintainers to alter project metadata, bypassing UI restrictions.
  • Organizations should update Harbor to versions 2.9.5, 2.10.3, or 2.11.0.
  • AI-driven tools were used to find this vulnerability.

Membership Required

 You must be a member to access this content.

View Membership Levels
Already a member? Log in here