If you're using Harbor as your container registry, bear in mind it can be hijacked with has_admin_role = True

If you're using Harbor as your container registry, bear in mind it can be hijacked with has_admin_role = True

5 years ago
Anonymous $4ckUSNo_FL

https://www.theregister.co.uk/2019/09/19/harbor_registry_patch/

Video IT departments using the Harbor container registry will want to update the software ASAP, following Thursday's disclosure of a bug that can be exploited by users to gain administrator privileges.

Aviv Sasson, of Palo Alto Networks' Unit 42 security team, found that under its default settings, Harbor accepts an API call that can, inadvertently, elevate a normal user's permissions. If you can reach a vulnerable Harbor installation's web interface, you can potentially pwn it.