CVE-2026-92770
Harbor through 2.15.2 fails to properly restrict the q query parameter filtering on scanner registration access credentials. Project administrators can exploit fuzzy filtering on the AccessCredential column to recover the scanner adapter secret one character at a time through response row counts.
वीकनेस
Harbor through 2.15.2 fails to properly restrict the q query parameter filtering on scanner registration access credentials. Project administrators can exploit fuzzy filtering on the AccessCredential column to recover the scanner adapter secret one character at a time through response row counts.
संदर्भ
- https://github.com/geo-chen/oss/blob/main/harbor.md
- https://github.com/goharbor/harbor
- https://github.com/goharbor/harbor/blob/v2.15.1/src/pkg/scan/dao/scanner/model.go#L51
- https://github.com/goharbor/harbor/blob/v2.15.1/src/pkg/user/dao/user.go#L35-L42
- https://www.vulncheck.com/advisories/harbor-through-2.15.2-scanner-credential-disclosure-via-query-parameter
हमलावर से पहले बग आप ढूँढें।
GitHub से साइन इन करें और एक मिनट से भी कम में अपना पहला ऑडिट चलाएँ। फ़्री प्लान के लिए क्रेडिट कार्ड की ज़रूरत नहीं।