CVE-2019-19030: Linuxfoundation Harbor

Medium severity, CVSS 5.3. EPSS: 1.9% chance of exploitation in the next 30 days.

Cloud Native Computing Foundation Harbor before 1.10.3 and 2.x before 2.0.1 allows resource enumeration because unauthenticated API calls reveal (via the HTTP status code) whether a resource exists.

Affected products

  • Linuxfoundation Harbor: before 1.10.3 (fixed in 1.10.3); from 2.0.0, before 2.0.1 (fixed in 2.0.1)

Published 2022-12-26. Last modified 2026-06-17.