Cloud Native Computing Foundation Harbor before 1.10.3 and 2.x before 2.0.1 allows resource enumeration because unauthenticated API calls reveal (via the HTTP status code) whether a resource exists.
| Software | From | Fixed in |
|---|---|---|
| linuxfoundation / harbor | 2.0.0 | 2.0.1 |
| linuxfoundation / harbor | - | 1.10.3 |
github.com/goharbor/harbor
|
1.7.0 | 1.10.3 |
github.com/goharbor/harbor
|
2.0.0 | 2.0.1 |