CVE-2019-19030
13Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 5.3epss 1.9%
exploitation probability
1.9%top 22% of all CVEs
observed exploitation
nono source reports it
In short
Harbor's API reveals whether resources exist by returning different HTTP status codes to unauthenticated users, allowing attackers to discover what projects, repositories, or other resources are stored in the system without needing login credentials.
Technical detail
CWE-204 information disclosure vulnerability in Harbor API endpoints that respond with status codes (e.g., 404 vs 403) allowing unauthenticated enumeration of resources. Requires no authentication; impact is disclosure of system inventory without authorization.
Summary generated and translated by AI from the official description.
Cloud Native Computing Foundation Harbor before 1.10.3 and 2.x before 2.0.1 allows resource enumeration because unauthenticated API calls reveal (via the HTTP status code) whether a resource exists.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Affected products
n/a · n/a