Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2019-16097

EPSS 93.58% · P100
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2019-16097

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
core/api/user.go in Harbor 1.7.0 through 1.8.2 allows non-admin users to create admin accounts via the POST /api/users API, when Harbor is setup with DB as authentication backend and allow user to do self-registration. Fixed version: v1.7.6 v1.8.3. v.1.9.0. Workaround without applying the fix: configure Harbor to use non-DB authentication backend such as LDAP.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
Harbor 权限许可和访问控制问题漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Harbor是一款开源的可信云本机注册表。该产品主要用于存储、签名和扫描容器映像以查找漏洞。 Harbor 1.7.0版本至1.8.2版本中的core/api/user.go文件存在权限许可和访问控制问题漏洞。攻击者可利用该漏洞创建admin账户。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Shenlong Deep Dive — AI Deep Analysis

10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2019-16097

#POC DescriptionSource LinkShenlong Link
1CVE-2019-16097 PoChttps://github.com/evilAdan0s/CVE-2019-16097POC Details
2CVE-2019-16097-batchhttps://github.com/rockmelodies/CVE-2019-16097-batchPOC Details
3Nonehttps://github.com/ianxtianxt/CVE-2019-16097POC Details
4cve-2019-1609https://github.com/dacade/cve-2019-16097POC Details
5harbor(<1.7.6/1.8.3) privilege escalation (CVE-2019-16097)https://github.com/theLSA/harbor-give-me-adminPOC Details
6Harbor 未授权创建管理员漏洞原理 docker及poc[基于pocsuite框架]https://github.com/luckybool1020/CVE-2019-16097POC Details
7A simple workflow that runs all Harbor related nuclei templates on a given target.https://github.com/projectdiscovery/nuclei-templates/blob/main/workflows/harbor-workflow.yamlPOC Details
8Harbor 1.7.0 through 1.8.2 is susceptible to privilege escalation via core/api/user.go, which allows allows non-admin users to create admin accounts via the POST /api/users API when Harbor is setup with DB as an authentication backend and allows user to do self-registration.https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2019/CVE-2019-16097.yamlPOC Details
9Nonehttps://github.com/Threekiii/Awesome-POC/blob/master/Web%E5%BA%94%E7%94%A8%E6%BC%8F%E6%B4%9E/Harbor%20%E6%9C%AA%E6%8E%88%E6%9D%83%E5%88%9B%E5%BB%BA%E7%AE%A1%E7%90%86%E5%91%98%E6%BC%8F%E6%B4%9E%20CVE-2019-16097.mdPOC Details
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2019-16097

登录查看更多情报信息。

Same Patch Batch · n/a · 2019-09-08 · 22 CVEs total

CVE-2019-16102Silver Peak Systems EdgeConnect SD-WAN 输入验证错误漏洞
CVE-2019-16095libmysofa 缓冲区错误漏洞
CVE-2019-16094libmysofa 缓冲区错误漏洞
CVE-2019-16093libmysofa 缓冲区错误漏洞
CVE-2019-16092libmysofa 代码问题漏洞
CVE-2019-16091libmysofa 缓冲区错误漏洞
CVE-2019-16096Kilo 输入验证错误漏洞
CVE-2016-10937IMAPFilter 信任管理问题漏洞
CVE-2019-16105Silver Peak Systems EdgeConnect SD-WAN 路径遍历漏洞
CVE-2019-16104Silver Peak Systems EdgeConnect SD-WAN 跨站脚本漏洞
CVE-2019-16103Silver Peak Systems EdgeConnect SD-WAN 权限许可和访问控制问题漏洞
CVE-2019-16117WordPress photo-gallery插件跨站脚本漏洞
CVE-2019-16101Silver Peak Systems EdgeConnect SD-WAN 信息泄露漏洞
CVE-2019-16100Silver Peak Systems EdgeConnect SD-WAN 输入验证错误漏洞
CVE-2019-16099Silver Peak Systems EdgeConnect SD-WAN 跨站请求伪造漏洞
CVE-2019-16109Plataformatec Devise 输入验证错误漏洞
CVE-2019-16113Bludit 路径遍历漏洞
CVE-2019-16115Xpdf 缓冲区错误漏洞
CVE-2019-16120WordPress event-tickets插件注入漏洞
CVE-2019-16119WordPress photo-gallery插件SQL注入漏洞

Showing top 20 of 22 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2019-16097

No comments yet


Leave a comment