<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T16:05:50.308245+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bit-harbor-2023-20902</id>
    <title>BIT-harbor-2023-20902 — Timing attack risk in Harbor</title>
    <updated>2026-10-04T16:05:50.311446+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Bitnami: harbor</p>
<p>A timing condition in Harbor 2.6.x and below, Harbor 2.7.2 and below,  Harbor 2.8.2 and below, and Harbor 1.10.17 and below allows an attacker with network access to 
create jobs/stop job tasks and retrieve job task information.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bit-harbor-2023-20902"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-161284</id>
    <title>EUVD-2026-161284</title>
    <updated>2026-10-04T16:05:50.311506+00:00</updated>
    <content>EUVD-2026-161284</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-161284"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2023-20902</id>
    <title>fkie_cve-2023-20902</title>
    <updated>2026-10-04T16:05:50.311523+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A timing condition in Harbor 2.6.x and below, Harbor 2.7.2 and below,  Harbor 2.8.2 and below, and Harbor 1.10.17 and below allows an attacker with network access to 
create jobs/stop job tasks and retrieve job task information.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2023-20902"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-mq6f-5xh5-hgcf</id>
    <title>GHSA-mq6f-5xh5-hgcf — Harbor timing attack risk</title>
    <updated>2026-10-04T16:05:50.311545+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: github.com/goharbor/harbor</p>
<p>In the Harbor jobservice container, the comparison of secrets in the authenticator type is prone to timing attacks. The vulnerability occurs due to the following code: https://github.com/goharbor/harbor/blob/aaea068cceb4063ab89313d9785f2b40f35b0d63/src/jobservice/api/authenticator.go#L69-L69
To avoid this issue, constant time comparison should be used.
```
subtle.ConstantTimeCompare([]byte(expectedSecret), []byte(secret)) == 0
```</p>
<p>### Impact
This attack might be possible theoretically, but no workable proof of concept is available, and access complexity is set at High.
The jobservice exposes these APIs
```
Create a job task --- POST /api/v1/jobs    
Get job task information --- GET /api/v1/jobs/{job_id}
Stop job task ---  POST /api/v1/jobs/{job_id}
Get job log task ---  GET /api/v1/jobs/{job_id}/log
Get job execution --- GET /api/v1/jobs/{job_id}/executions
Get job stats ---  GET /api/v1/stats
Get job service configuration ---  GET /api/v1/config
```
It is used to create jobs/stop job tasks and retrieve job task information.  If an attacker obtains the secrets, it is possible to retrieve the job information, create a job, or stop a job task.</p>
<p>The following versions of Harbor are involved:
&lt;=Harbor 2.8.2, &lt;=Harbor 2.7.2, &lt;= Harbor 2.6.x, &lt;=Harbor 1.10.17</p>
<p>### Patches
Harbor 2.8.3, Harbor 2.7.3, Harbor 1.10.18</p>
<p>### Workarounds
Because the jobservice only exposes HTTP service to harbor-core containers, blocking any inbound traffic from the external network to the jobservice…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-mq6f-5xh5-hgcf"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2023-20902</id>
    <title>gsd-2023-20902</title>
    <updated>2026-10-04T16:05:50.311586+00:00</updated>
    <content>gsd-2023-20902</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2023-20902"/>
  </entry>
</feed>
