Loading
Generated remediation guidance and an executive summary. No account required.
Harbor fails to validate user permissions while deleting Webhook policies, allowing malicious users to view, update and delete Webhook policies of other users. The attacker could modify Webhook policies configured in other projects.
Use CWE-285, Linuxfoundation vendor hub and Harbor product page to widen CVE-2022-31666 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2022-31670, CVE-2022-46463 and CVE-2022-31671 for nearby disclosures in the same product family.