Cloud Native Computing Foundation Harbor before 1.10.3 and 2.x before 2.0.1 allows resource enumeration because unauthenticated API calls reveal (via the HTTP status code) whether a resource exists.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Harbor | Linuxfoundation | * | 1.10.3 (excluding) |
Harbor | Linuxfoundation | 2.0.0 (including) | 2.0.1 (excluding) |