CVE-2020-29662

EUVD-2022-0783
In Harbor 2.0 before 2.0.5 and 2.1.x before 2.1.2 the catalog’s registry API is exposed on an unauthenticated path.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5.3 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 45%
Affected Products (NVD)
VendorProductVersion
linuxfoundationharbor
2.0 ≤
𝑥
< 2.0.5
linuxfoundationharbor
2.1.0 ≤
𝑥
< 2.1.2
𝑥
= Vulnerable software versions