CVE-2023-20902: Linuxfoundation Harbor

Medium severity, CVSS 6.5. EPSS: 0.4% chance of exploitation in the next 30 days.

A timing condition in Harbor 2.6.x and below, Harbor 2.7.2 and below,  Harbor 2.8.2 and below, and Harbor 1.10.17 and below allows an attacker with network access to create jobs/stop job tasks and retrieve job task information.

Affected products

  • Linuxfoundation Harbor: before 1.10.17 (fixed in 1.10.17); from 2.6.0, up to and including 2.6.4; from 2.7.0, before 2.7.3 (fixed in 2.7.3); from 2.8.0, before 2.8.3 (fixed in 2.8.3)

Published 2023-11-09. Last modified 2026-06-17.