Identifying a BOLA Vulnerability in Harbor, a Cloud-Native Container Registry
ID: c8451118-04f1-517f-afff-d1e0b674bf9b
STIX ID: report--c8451118-04f1-517f-afff-d1e0b674bf9b
Feed Name: Palo Alto Networks Unit 42
Unit 42 researchers disclosed a broken object-level authorization (BOLA) vulnerability (CVE-2024-22278, CVSS 6.4) in Harbor versions prior to the patched releases; the issue lets users with a Maintainer role modify project metadata via Harbor APIs (create/update/delete), enabling actions such as making projects public, bypassing vulnerability scanning, and deploying unverified images—Harbor released fixes in v2.9.5, v2.10.3 and v2.11.0 and users are advised to upgrade immediately.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
