HomeSecurity1,300 Harbor cloud storage spaces vulnerable to attacks: Update immediately!

1,300 Harbor cloud storage spaces vulnerable to attacks: Update immediately!

Researchers from Palo Alto Networks' Unit 42 have discovered a critical vulnerability in a popular cloud open-source system. The vulnerability allows malicious hackers to gain access to storage with administrator privileges . The discovery was made by chance while analyzing projects associated with the Cloud Native Computing Foundation ( CNCF ). The software in which the vulnerability was found is Harbor .Harbor

Harbor is open sourceused to store and scan container images. Harbor is compatible with Docker Hub, Docker Registry, Google Container Registry, and others.

One of the Palo Alto Networks researchers said that the vulnerability, found in Harbor, versions firmware 1.7.0 – 1.8.2. The researchers named the vulnerability CVE-2019-16097.

As we said above, this is a "privilege escalation" vulnerability, a vulnerability that gives administrator privileges to the attacker, by default.

1,300 Harbor cloud storage spaces vulnerable to attacks: Update immediately!

Aviv Sasson, a researcher at Palo Alto Networks, managed to write a Python script to exploit the vulnerability. This could easily be done by attackers.

If hackers gain access to Harbor's storage, they can download private projects, delete images, or upload their own, which may contain malware, such as cryptominers and more.

"I recommend that all users update to Harbor because this vulnerability is critical," Sasson said.

Researchers say the risk is high. 1,300 vulnerable Harbor repositories have already been found , due to default settings. The problem will only be addressed by updating the software.

The team behind Harbor released an update yesterday toresolve the security.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS