CVE-2019-19029: SQL Injection via user-groups in VMware Harbor Container Registry for Pivotal Platform

23867

04 December 2019

04 December 2019

CLOSED

HIGH

CVE-2019-19029

Severity

High

Vendor

Pivotal

Description

It was discovered that in VMware Harbor Container Registry for Pivotal Platform, versions prior to 1.8.6 and 1.9.3, a user with Project-Admin capabilities can utilize and exploit SQL Injection to read secrets from the underlying database or conduct privilege escalation.

Affected VMware Products and Versions

Severity is high unless otherwise noted.

  • VMware Harbor Container Registry for Pivotal Platform
    • 1.8 versions prior to 1.8.6
    • 1.9 versions prior to 1.9.3

Mitigation

  • VMware Harbor Container Registry for Pivotal Platform
    • 1.8.6
    • 1.9.3

Credit

This issue was responsibly reported by Cure53.

References

History

2019-12-04: Initial vulnerability report published.