We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.
Please see our statement on Data Privacy.
Harbor is an open source trusted cloud native registry project that stores, signs, and scans content. Versions 2.11.2 and below, as well as versions 2.12.0-rc1 and 2.13.0-rc1, contain a vulnerability where the markdown field in the info tab page can be exploited to inject XSS code. This is fixed in versions 2.11.3 and 2.12.3.
Reserved 2025-04-01 | Published 2025-07-23 | Updated 2025-07-23 | Assigner GitHub_MCWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
github.com/...harbor/security/advisories/GHSA-f9vc-vf3r-pqqq
github.com/...ommit/76c2c5f7cfd9edb356cbb373889a59cc3217a058
github.com/...ommit/a13a16383a41a8e20f524593cb290dc52f86f088
github.com/...ommit/f019430872118852f83f96cac9c587b89052d1e5
Support options