VulnerabilityModified
CVE-2019-19026
Cloud Native Computing Foundation Harbor prior to 1.8.6 and 1.9.3 allows SQL Injection via project quotas in the VMware Harbor Container Registry for the Pivotal Platform.
MEDIUM 4.9EPSS 1.42%
Does this matter?
Lower severity and a low EPSS score (1.42%). Track it; it rarely justifies an emergency change on its own.
Description
Cloud Native Computing Foundation Harbor prior to 1.8.6 and 1.9.3 allows SQL Injection via project quotas in the VMware Harbor Container Registry for the Pivotal Platform.
- CVSS 3.1
- 4.9 MEDIUMCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 1.42% probability · 71th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-89
- Affected
- linuxfoundation/harbor · pivotal/vmware harbor registry
- Source
- cve@mitre.org
References
- https://github.com/goharbor/harbor/security/advisoriesThird Party Advisory
- https://github.com/goharbor/harbor/security/advisories/GHSA-rh89-vvrg-fg64Third Party Advisory
- https://tanzu.vmware.com/security/cve-2019-19026Third Party Advisory
- https://github.com/goharbor/harbor/security/advisoriesThird Party Advisory
- https://github.com/goharbor/harbor/security/advisories/GHSA-rh89-vvrg-fg64Third Party Advisory
- https://tanzu.vmware.com/security/cve-2019-19026Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.