logo

Identifying a BOLA Vulnerability in Harbor, a Cloud-Native Container Registry

ID: c8451118-04f1-517f-afff-d1e0b674bf9b

STIX ID: report--c8451118-04f1-517f-afff-d1e0b674bf9b

Feed Name: Palo Alto Networks Unit 42

Threat Score
55/100

Date Published: 2024-07-31

Date Updated: 2026-04-28

Author: Jay Chen and Ravid Mazon

...
...

Unit 42 researchers disclosed a broken object-level authorization (BOLA) vulnerability (CVE-2024-22278, CVSS 6.4) in Harbor versions prior to the patched releases; the issue lets users with a Maintainer role modify project metadata via Harbor APIs (create/update/delete), enabling actions such as making projects public, bypassing vulnerability scanning, and deploying unverified images—Harbor released fixes in v2.9.5, v2.10.3 and v2.11.0 and users are advised to upgrade immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.