Loading
Generated remediation guidance and an executive summary. No account required.
Harbor fails to validate the user permissions when updating tag retention policies. By sending a request to update a tag retention policy with an id that belongs to a project that the currently authenticated user doesn’t have access to, the attacker could modify tag retention policies configured in other projects.
Use CWE-285, Linuxfoundation vendor hub and Harbor product page to widen CVE-2022-31670 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2022-31666, CVE-2022-46463 and CVE-2022-31671 for nearby disclosures in the same product family.