SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2019-19030

Cloud Native Computing Foundation Harbor before 1.10.3 and 2.x before 2.0.1 allows resource enumeration because unauthenticated API calls reveal (via the HTTP status code) whether a resource exists.

MEDIUM 5.3EPSS 1.89%

Does this matter?

Lower severity and a low EPSS score (1.89%). Track it; it rarely justifies an emergency change on its own.

Description

Cloud Native Computing Foundation Harbor before 1.10.3 and 2.x before 2.0.1 allows resource enumeration because unauthenticated API calls reveal (via the HTTP status code) whether a resource exists.

CVSS 3.1
5.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
EPSS
1.89% probability · 78th percentile
CISA KEV
Not listed
Weakness
CWE-204
Affected
linuxfoundation/harbor
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.