CVE-2022-31667

Harbor fails to validate the user permissions when updating a robot account thatbelongs to a project that the authenticated user doesnt have access to.

By sending a request that attempts to update a robot account, and specifying a robotaccount id and robot account name that belongs to a different project that the userdoesnt have access to, it was possible to revoke the robot account permissions.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6.4 MEDIUM
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:L
vmwareCNA
6.4 MEDIUM
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:L
CISA-ADPADP
---
---