If you're using Harbor as your container registry, bear in mind it can be hijacked with has_admin_role = True

If you're using Harbor as your container registry, bear in mind it can be hijacked with has_admin_role = True

Patch now before miscreants sail off with your apps, data


Video IT departments using the Harbor container registry will want to update the software ASAP, following Thursday's disclosure of a bug that can be exploited by users to gain administrator privileges.


Aviv Sasson, of Palo Alto Networks' Unit 42 security team, found that under its default settings, Harbor accepts an API call that can, inadvertently, elevate a normal user's permissions. If you can reach a vulnerable Harbor installation's web interface, you can potentially pwn it.


Seeing as Harbor is used by enterprises and cloud platforms to manage collections of Docker and Kubernetes containers, which themselves contain applications and other resources, gaining administrative access is a big deal: a rogue admin can swipe data from the registry, or tamper with containers to ..

Support the originator by clicking the read the rest link below.