create jobs/stop job tasks and retrieve job task information.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-2779 | A timing condition in Harbor 2.6.x and below, Harbor 2.7.2 and below, Harbor 2.8.2 and below, and Harbor 1.10.17 and below allows an attacker with network access to create jobs/stop job tasks and retrieve job task information. |
Github GHSA |
GHSA-mq6f-5xh5-hgcf | Harbor timing attack risk |
No history.
Status: PUBLISHED
Assigner: vmware
Published:
Updated: 2024-09-04T13:18:17.730Z
Reserved: 2022-11-01T15:41:50.396Z
Link: CVE-2023-20902
Updated: 2024-08-02T09:21:33.417Z
Status : Modified
Published: 2023-11-09T01:15:07.660
Modified: 2026-06-17T05:31:08.990
Link: CVE-2023-20902
No data.
OpenCVE Enrichment
No data.
-
CWE-362
Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
EUVD
Github GHSA