SB2017121527 - Server-Side Request Forgery (SSRF) in Harbor
Published: December 15, 2017 Updated: August 8, 2020
Security Bulletin ID
SB2017121527
Severity
High
Patch available
YES
Number of vulnerabilities
1
Exploitation vector
Remote access
Highest impact
Information disclosure
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Server-Side Request Forgery (SSRF) (CVE-ID: CVE-2017-17697)
The vulnerability allows a remote non-authenticated attacker to gain access to sensitive information.
The Ping() function in ui/api/target.go in Harbor through 1.3.0-rc4 has SSRF via the endpoint parameter to /api/targets/ping.
Remediation
Install update from vendor's website.