CVE-2019-19026

medium

Description

Cloud Native Computing Foundation Harbor prior to 1.8.6 and 1.9.3 allows SQL Injection via project quotas in the VMware Harbor Container Registry for the Pivotal Platform.

References

https://tanzu.vmware.com/security/cve-2019-19026

https://github.com/goharbor/harbor/security/advisories/GHSA-rh89-vvrg-fg64

https://github.com/goharbor/harbor/security/advisories

Details

Source: Mitre, NVD

Published: 2020-03-20

Updated: 2021-05-21

Risk Information

CVSS v2

Base Score: 4

Vector: CVSS2#AV:N/AC:L/Au:S/C:P/I:N/A:N

Severity: Medium

CVSS v3

Base Score: 4.9

Vector: CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N

Severity: Medium