{"id":"CVE-2019-19030","aliases":["GHSA-q9x4-q76f-5h5j","GO-2022-0704"],"url":"https://o3.security/vulnerability/CVE-2019-19030","summary":"Unauthenticated users can exploit an enumeration vulnerability in Harbor (CVE-2019-19030)","details":"Cloud Native Computing Foundation Harbor before 1.10.3 and 2.x before 2.0.1 allows resource enumeration because unauthenticated API calls reveal (via the HTTP status code) whether a resource exists.","published":"2022-12-26T22:15:10.247Z","modified":"2026-08-07T15:18:13.269018Z","cvss":{"score":5.3,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":1,"affectedPackages":[{"ecosystem":"Go","name":"github.com/goharbor/harbor","fixedVersion":"1.10.3"},{"ecosystem":"Go","name":"github.com/goharbor/harbor","fixedVersion":"2.0.1"}],"fix":null,"references":[{"type":"EVIDENCE","url":"https://github.com/goharbor/harbor/security/advisories/GHSA-q9x4-q76f-5h5j"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-07T15:18:13.269018Z"}}