Harbor repository description page has Cross-site Scripting vulnerability
Package
Affected versions
>= 2.12.0-rc1, < 2.12.4-rc1
>= 2.13.0-rc1, < 2.13.1-rc1
>= 2.4.0-rc1.1, <= 2.11.2
< 2.4.0-rc1.0.20250421072404-a13a16383a41
Patched versions
2.12.4-rc1
2.13.1-rc1
2.4.0-rc1.0.20250421072404-a13a16383a41
Description
Published to the GitHub Advisory Database
Jul 23, 2025
Reviewed
Jul 23, 2025
Published by the National Vulnerability Database
Jul 23, 2025
Last updated
Jul 23, 2025
Impact
In the Harbor repository information, it is possible to inject code resulting in a stored XSS issue.
Patches
Harbor v2.12.3 Harbor 2.11.3
Workarounds
No
References
Credit
gleb.razvitie@gmail.com
References