<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 16:05:39 +0000</lastBuildDate>
    <item>
      <title>BIT-harbor-2023-20902 — Timing attack risk in Harbor</title>
      <link>https://cve.radiocsirt.org/vuln/bit-harbor-2023-20902</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: harbor&lt;/p&gt;
&lt;p&gt;A timing condition in Harbor 2.6.x and below, Harbor 2.7.2 and below,  Harbor 2.8.2 and below, and Harbor 1.10.17 and below allows an attacker with network access to 
create jobs/stop job tasks and retrieve job task information.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: harbor&lt;/p&gt;
&lt;p&gt;A timing condition in Harbor 2.6.x and below, Harbor 2.7.2 and below,  Harbor 2.8.2 and below, and Harbor 1.10.17 and below allows an attacker with network access to 
create jobs/stop job tasks and retrieve job task information.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bit-harbor-2023-20902</guid>
    </item>
    <item>
      <title>EUVD-2026-161284</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-161284</link>
      <description>EUVD-2026-161284</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-161284</guid>
    </item>
    <item>
      <title>fkie_cve-2023-20902</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2023-20902</link>
      <description>&lt;p&gt;A timing condition in Harbor 2.6.x and below, Harbor 2.7.2 and below,  Harbor 2.8.2 and below, and Harbor 1.10.17 and below allows an attacker with network access to 
create jobs/stop job tasks and retrieve job task information.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A timing condition in Harbor 2.6.x and below, Harbor 2.7.2 and below,  Harbor 2.8.2 and below, and Harbor 1.10.17 and below allows an attacker with network access to 
create jobs/stop job tasks and retrieve job task information.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2023-20902</guid>
    </item>
    <item>
      <title>GHSA-mq6f-5xh5-hgcf — Harbor timing attack risk</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-mq6f-5xh5-hgcf</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/goharbor/harbor&lt;/p&gt;
&lt;p&gt;In the Harbor jobservice container, the comparison of secrets in the authenticator type is prone to timing attacks. The vulnerability occurs due to the following code: https://github.com/goharbor/harbor/blob/aaea068cceb4063ab89313d9785f2b40f35b0d63/src/jobservice/api/authenticator.go#L69-L69
To avoid this issue, constant time comparison should be used.
```
subtle.ConstantTimeCompare([]byte(expectedSecret), []byte(secret)) == 0
```&lt;/p&gt;
&lt;p&gt;### Impact
This attack might be possible theoretically, but no workable proof of concept is available, and access complexity is set at High.
The jobservice exposes these APIs
```
Create a job task --- POST /api/v1/jobs    
Get job task information --- GET /api/v1/jobs/{job_id}
Stop job task ---  POST /api/v1/jobs/{job_id}
Get job log task ---  GET /api/v1/jobs/{job_id}/log
Get job execution --- GET /api/v1/jobs/{job_id}/executions
Get job stats ---  GET /api/v1/stats
Get job service configuration ---  GET /api/v1/config
```
It is used to create jobs/stop job tasks and retrieve job task information.  If an attacker obtains the secrets, it is possible to retrieve the job information, create a job, or stop a job task.&lt;/p&gt;
&lt;p&gt;The following versions of Harbor are involved:
&amp;lt;=Harbor 2.8.2, &amp;lt;=Harbor 2.7.2, &amp;lt;= Harbor 2.6.x, &amp;lt;=Harbor 1.10.17&lt;/p&gt;
&lt;p&gt;### Patches
Harbor 2.8.3, Harbor 2.7.3, Harbor 1.10.18&lt;/p&gt;
&lt;p&gt;### Workarounds
Because the jobservice only exposes HTTP service to harbor-core containers, blocking any inbound traffic from the external network to the jobservice…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/goharbor/harbor&lt;/p&gt;
&lt;p&gt;In the Harbor jobservice container, the comparison of secrets in the authenticator type is prone to timing attacks. The vulnerability occurs due to the following code: https://github.com/goharbor/harbor/blob/aaea068cceb4063ab89313d9785f2b40f35b0d63/src/jobservice/api/authenticator.go#L69-L69
To avoid this issue, constant time comparison should be used.
```
subtle.ConstantTimeCompare([]byte(expectedSecret), []byte(secret)) == 0
```&lt;/p&gt;
&lt;p&gt;### Impact
This attack might be possible theoretically, but no workable proof of concept is available, and access complexity is set at High.
The jobservice exposes these APIs
```
Create a job task --- POST /api/v1/jobs    
Get job task information --- GET /api/v1/jobs/{job_id}
Stop job task ---  POST /api/v1/jobs/{job_id}
Get job log task ---  GET /api/v1/jobs/{job_id}/log
Get job execution --- GET /api/v1/jobs/{job_id}/executions
Get job stats ---  GET /api/v1/stats
Get job service configuration ---  GET /api/v1/config
```
It is used to create jobs/stop job tasks and retrieve job task information.  If an attacker obtains the secrets, it is possible to retrieve the job information, create a job, or stop a job task.&lt;/p&gt;
&lt;p&gt;The following versions of Harbor are involved:
&amp;lt;=Harbor 2.8.2, &amp;lt;=Harbor 2.7.2, &amp;lt;= Harbor 2.6.x, &amp;lt;=Harbor 1.10.17&lt;/p&gt;
&lt;p&gt;### Patches
Harbor 2.8.3, Harbor 2.7.3, Harbor 1.10.18&lt;/p&gt;
&lt;p&gt;### Workarounds
Because the jobservice only exposes HTTP service to harbor-core containers, blocking any inbound traffic from the external network to the jobservice…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-mq6f-5xh5-hgcf</guid>
    </item>
    <item>
      <title>gsd-2023-20902</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2023-20902</link>
      <description>gsd-2023-20902</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2023-20902</guid>
    </item>
  </channel>
</rss>
