VMware Update
3414Warning Date
Severity Level
Warning Number
Target Sector
16 October, 2019
● Critical
2019-523
All
Description:
VMware has released security update to address a vulnerability in the following products:
- VMware Harbor Container Registry for PCF versions: 1.7.x - 1.8.x
- VMware Cloud Foundation *Affected if the optional 'Harbor Registry' component has been deployed.
Threats:
Attacker with administrative privilege could exploit this vulnerability by accessing a project then creating a robot account inside of an adjacent project via the Harbor API which may lead to an unauthorized access to push/pull/modify images in the target adjacent project.
Best practice and Recommendations:
The CERT team encourages users to review VMware security advisory and apply the necessary updates: https://www.vmware.com/security/advisories/VMSA-2019-0016.html