S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Jan 7, 2024

CVE-2019-16097 Scanner

CVE-2019-16097 scanner - Privilege Escalation vulnerability in Harbor

Est. Time~15 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.6k
Times Used
continuous scan runs
4.4k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2019-16097
6.5
CVSS

core/api/user.go in Harbor 1.7.0 through 1.8.2 allows non-admin users to create admin accounts via the POST /api/users API, when Harbor is setup with DB as authentication backend and allow user to do self-registration. Fixed version: v1.7.6 v1.8.3. v.1.9.0. Workaround without applying the fix: configure Harbor to use non-DB authentication backend such as LDAP.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 21, 2026View on NVD →
Detail

Harbor is an open-source container image registry that is used to store, manage and distribute Docker images. It is designed to provide an enterprise-class registry server, allowing organizations to securely store and manage their images. Harbor has become a popular choice for developers due to its support for role-based access control, image replication, and vulnerability scanning capabilities.

Recently, a vulnerability was detected in Harbor software, known as CVE-2019-16097. This flaw allowed non-admin users to create admin accounts through the POST /api/users API, when Harbor was set up with DB as authentication backend. The vulnerability was present in Harbor 1.7.0 through 1.8.2, which made it possible for attackers to exploit it to gain unauthorized access to the system.

The exploitation of CVE-2019-16097 could have dire consequences for organizations. It could allow attackers to gain admin-level access to the Harbor server, which could lead to a complete compromise of the organization's container image registry. Attackers could use this access to alter images, inject malicious code or perform other harmful actions that could lead to data breaches or system failures.

Thanks to the Pro features of the s4e.io platform, you can easily and quickly learn about vulnerabilities in your digital assets. With regular scanning and monitoring, you can stay ahead of potential threats and keep your systems secure. Don't wait for the next security flaw to emerge, take proactive measures to protect your systems today.

 

REFERENCES

Solution Advice

To protect against this vulnerability, the following precautions can be taken:

  • Update to the latest version of Harbor that includes the fix for the CVE-2019-16097 vulnerability.
  • If unable to update Harbor, configure it to use non-DB authentication backend such as LDAP.
  • Conduct regular vulnerability scanning and penetration testing to identify and remediate any issues in the system.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2019-16097 scanner - Privilege Escalation vulnerability in Harbor | S4E