Database/Control plane, storage & DevOps
Harbor registry: P2P preheat execution logs readable/updatable by any authenticated user via job ID enumeration
CVSS 7.4CVE-2022-31671Control plane, storage & DevOpscurated
Impact
P2P preheat execution logs readable/updatable by any authenticated user via job ID enumeration
Who can reach it
Network (remote)
What to do
Control-plane: upgrade; job logs often contain registry credentials
References
Related entries
- MinIO (admin server-update API): An authenticated request to the server-update admin API traverses out of the intendedCVE-2022-35919 · MinIO (admin server-update API)High
- Cisco Nexus 3000/9000 (health monitoring diagnostics): The health monitoring diagnostics subsystem on Nexus 3000 andCVE-2025-20111 · Cisco Nexus 3000/9000 (health monitoring diagnostics)High
- Confluent Kafka Python client: TLS certificate verification disabled by default toward HashiCorp Vault KMSCVE-2026-15911 · Confluent Kafka Python client (HashiCorp Vault KMS integration)High
- N-able N-central: Authentication bypass using an alternate path or channel on the RMM serverCVE-2026-18556 · N-able N-centralHigh
- Jenkins TICS plugin: attacker-controlled build variables execute arbitrary commands on the build agentCVE-2026-84675 · Jenkins TICS plugin (build environment variable expansion into an OS command)High
- Sigstore cosign (verify-blob / verify-blob-attestation, legacy JSON bundle): SUPPLY CHAIN, VERIFICATION BYPASS: keylessNCVD-2026-056-sigstore-cosign-verify-blob-veri · Sigstore cosign (verify-blob / verify-blob-attestation, legacy JSON bundle)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.