CVE Database
/

CVE-2019-3990

Back to search

CVE-2019-3990

Published: Dec 3, 2019

Modified: Aug 4, 2024

PUBLISHED

Description

A User Enumeration flaw exists in Harbor. The issue is present in the "/users" API endpoint. This endpoint is supposed to be restricted to administrators. This restriction is able to be bypassed and information can be obtained about registered users can be obtained via the "search" functionality.

VendorProductVersions

n/a

Harbor

affected
Harbor versions 1.9.1 and prior

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now