Use of hard coded credentials in GoHarbor Harbor version 2.15.0 and below, allows attackers to use the default password and gain access to the web UI.
Attack Parameters
Impact Assessment
CVSS Vector v3.1
Weakness Type (CWE)
Vulnerable Products 1
| Configuration | From (including) | Up to (excluding) |
|---|---|---|
|
Linuxfoundation Harbor
cpe:2.3:a:linuxfoundation:harbor:*:*:*:*:*:*:*:*
|
— |
<= 2.15.0
|