Researchers from Palo Alto Networks' Unit 42 have discovered a critical vulnerability in a popular cloud open-source system. The vulnerability allows malicious hackers to gain access to storage with administrator privileges . The discovery was made by chance while analyzing projects associated with the Cloud Native Computing Foundation ( CNCF ). The software in which the vulnerability was found is Harbor .
Harbor is open sourceused to store and scan container images. Harbor is compatible with Docker Hub, Docker Registry, Google Container Registry, and others.
One of the Palo Alto Networks researchers said that the vulnerability, found in Harbor, versions firmware 1.7.0 – 1.8.2. The researchers named the vulnerability CVE-2019-16097.
As we said above, this is a "privilege escalation" vulnerability, a vulnerability that gives administrator privileges to the attacker, by default.

Aviv Sasson, a researcher at Palo Alto Networks, managed to write a Python script to exploit the vulnerability. This could easily be done by attackers.
If hackers gain access to Harbor's storage, they can download private projects, delete images, or upload their own, which may contain malware, such as cryptominers and more.
"I recommend that all users update to Harbor because this vulnerability is critical," Sasson said.
Researchers say the risk is high. 1,300 vulnerable Harbor repositories have already been found , due to default settings. The problem will only be addressed by updating the software.
The team behind Harbor released an update yesterday toresolve the security.
