CVE-2019-3990: Linuxfoundation Harbor
Medium severity, CVSS 4.3. EPSS: 1% chance of exploitation in the next 30 days.
A User Enumeration flaw exists in Harbor. The issue is present in the "/users" API endpoint. This endpoint is supposed to be restricted to administrators. This restriction is able to be bypassed and information can be obtained about registered users can be obtained via the "search" functionality.
Affected products
- Linuxfoundation Harbor: from 1.7.0, up to and including 1.7.6; from 1.8.0, up to and including 1.8.5; version 1.9.0 only; version 1.9.1 only
Published 2019-12-03. Last modified 2026-06-17.