QID 995545

Date Published: 2023-10-11

QID 995545: GO (Go) Security Update for github.com/goharbor/harbor (GHSA-mq6f-5xh5-hgcf)

In the Harbor jobservice container, the comparison of secrets in the authenticator type is prone to timing attacks. The vulnerability occurs due to the following code: https://github.com/goharbor/harbor/blob/aaea068cceb4063ab89313d9785f2b40f35b0d63/src/jobservice/api/authenticator.go#L69-L69 To avoid this issue, constant time comparison should be used.

Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.

  • CVSS V3 rated as Critical - 8.6 severity.
  • CVSS V2 rated as Medium - 5.4 severity.
  • Solution
    Refer to Github security advisory GHSA-mq6f-5xh5-hgcf for updates and patch information.
    Vendor References

    CVEs related to QID 995545

    Software Advisories
    Advisory ID Software Component Link
    GHSA-mq6f-5xh5-hgcf github.com/goharbor/harbor URL Logo github.com/advisories/GHSA-mq6f-5xh5-hgcf