CVE-2019-19023
Harbor vulnerability analysis and mitigation

Overview

Cloud Native Computing Foundation Harbor, in versions prior to 1.8.6 and 1.9.3, contained a privilege escalation vulnerability in the VMware Harbor Container Registry for the Pivotal Platform. The vulnerability was disclosed in December 2019 and assigned CVE-2019-19023. The vulnerability affected Harbor container registry installations across multiple versions (VMware Advisory, NVD).

Technical details

The vulnerability received a CVSS v3.1 base score of 8.8 (HIGH) with the vector string CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H. The vulnerability stems from the Harbor API's failure to enforce proper permissions and scope on API requests to modify email addresses. This security flaw allows manipulation of user email addresses through API calls without appropriate permission validation (VMware Advisory).

Impact

The vulnerability allows a normal user to gain administrator account privileges through unauthorized elevation. An attacker could exploit this by making an API call to modify the email address of a specific user, then reset the password for that email address to gain access to the account with elevated privileges (VMware Advisory).

Mitigation and workarounds

Organizations running affected versions should upgrade to Harbor version 1.8.6 or 1.9.3, depending on their current version track. These patched versions include fixes for the privilege escalation vulnerability (VMware Advisory).

Additional resources


SourceThis report was generated using AI

Related Harbor vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2022-31670HIGH7.7
  • HarborHarbor
  • cpe:2.3:a:linuxfoundation:harbor
NoYesNov 14, 2024
CVE-2022-31669HIGH7.7
  • HarborHarbor
  • harbor
NoYesNov 14, 2024
CVE-2022-31671HIGH7.4
  • HarborHarbor
  • cpe:2.3:a:linuxfoundation:harbor
NoYesNov 14, 2024
CVE-2025-30086MEDIUM4.9
  • HarborHarbor
  • github.com/goharbor/harbor
NoYesJul 25, 2025
CVE-2025-32019MEDIUM4.1
  • HarborHarbor
  • cpe:2.3:a:linuxfoundation:harbor
NoYesJul 23, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management