Official company update

SSRF in Harbor Webhooks: Any User Can Reach the Server’s Cloud Credentials

OX Security·ox.security·

What the source says

OX Research disclosed an SSRF vulnerability in Harbor, the CNCF open-source container registry. Any registered user who can create a project can point a webhook at the cloud metadata endpoint and walk away with the server’s IAM credentials. No admin role, no user interaction, and no need to stay online. Set the webhook, wait for […] The post SSRF in Harbor W

Checking access…

The original publication, including any images and updates, remains with the publisher.

Checking free source access…

More about OX Security