If you’re using Harbor as your container registry, bear in mind it can be hijacked with has_admin_role = True

IT departments using the Harbor container registry will want to update the software ASAP, following Thursday’s disclosure of a bug that can be exploited by users to gain administrator privileges. Aviv Sasson, of Palo Alto Networks’ Unit 42 security team, found that under its default settings, Harbor accepts an API call that can, inadvertently, elevate a normal user’s permissions.

Read full article on The Register

 


Date:

Categorie(s):

Tag(s):