Cloud Native Computing Foundation Harbor before 1.10.3 and 2.x before 2.0.1 allows resource enumeration because unauthenticated API calls reveal (via the HTTP status code) whether a resource exists.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| github.com/goharbor/harbor(Go) | 1.7.0 | 1.10.3 | N/A |
| github.com/goharbor/harbor(Go) | 2.0.0 | 2.0.1 | N/A |
CVSS Metrics