« Volver al listado

CVE-2025-32019

Estado: AplazadaMedia (4.1)—

Harbor is an open source trusted cloud native registry project that stores, signs, and scans content. Versions 2.11.2 and below, as well as versions 2.12.0-rc1 and 2.13.0-rc1, contain a vulnerability where the markdown field in the info tab page can be exploited to inject XSS code. This is fixed in versions 2.11.3 and 2.12.3.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2025-32019",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2025-32019",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2025-07-23T20:47:38.788563Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "security-advisories@github.com",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 4.1,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 1.4,
        "exploitabilityScore": 2.3
      }
    ]
  },
  "affected": [
    {
      "source": "security-advisories@github.com",
      "affectedData": [
        {
          "vendor": "goharbor",
          "product": "harbor",
          "versions": [
            {
              "status": "affected",
              "version": ">= 2.12.0-rc1, < 2.12.4-rc1"
            },
            {
              "status": "affected",
              "version": ">= 2.13.0-rc1, < 2.13.1-rc1"
            },
            {
              "status": "affected",
              "version": "<= 2.4.0-rc1.1, < 2.11.3"
            }
          ]
        }
      ]
    }
  ],
  "published": "2025-07-23T21:15:26.037",
  "references": [
    {
      "url": "https://github.com/goharbor/harbor/commit/76c2c5f7cfd9edb356cbb373889a59cc3217a058",
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/goharbor/harbor/commit/a13a16383a41a8e20f524593cb290dc52f86f088",
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/goharbor/harbor/commit/f019430872118852f83f96cac9c587b89052d1e5",
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/goharbor/harbor/security/advisories/GHSA-f9vc-vf3r-pqqq",
      "source": "security-advisories@github.com"
    }
  ],
  "vulnStatus": "Deferred",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security-advisories@github.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-79"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Harbor is an open source trusted cloud native registry project that stores, signs, and scans content. Versions 2.11.2 and below, as well as versions 2.12.0-rc1 and 2.13.0-rc1, contain a vulnerability where the markdown field in the info tab page can be exploited to inject XSS code. This is fixed in versions 2.11.3 and 2.12.3."
    },
    {
      "lang": "es",
      "value": "Harbor es un proyecto de registro nativo en la nube, confiable y de código abierto que almacena, firma y escanea contenido. Las versiones 2.11.2 y anteriores, así como las versiones 2.12.0-rc1 y 2.13.0-rc1, contienen una vulnerabilidad que permite explotar el campo Markdown de la pestaña de información para inyectar código XSS. Esto se ha corregido en las versiones 2.11.3 y 2.12.3."
    }
  ],
  "lastModified": "2026-06-17T09:11:19.870",
  "sourceIdentifier": "security-advisories@github.com"
}