{"id":"GHSA-prh4-vhfh-24mj","aliases":["GO-2026-4876"],"url":"https://o3.security/vulnerability/GHSA-prh4-vhfh-24mj","summary":"Harbor: LDAP password and OIDC secret are not redacted in the audit log","details":"### Impact\nHarbor write configuration payload to audit log when configuration change, the ldap_search_password and oidc_client_secret will be logged in the audit log without redacted\n\n### Patches\nHarbor v2.15.0, v2.14.3, v2.13.5\n\n### Workarounds\nDisable audit log configure event in Harbor Web Console: Go to Administration -> Configuration -> Enable Audit Log Event Type -> Uncheck \"Update Configuration\" and click \"Save\" Button.","published":"2026-03-26T22:25:26Z","modified":"2026-04-08T05:18:55.793745Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Go","name":"github.com/goharbor/harbor","fixedVersion":"2.13.5"},{"ecosystem":"Go","name":"github.com/goharbor/harbor","fixedVersion":"2.14.3"}],"fix":{"url":"https://github.com/goharbor/harbor/commit/85e756486fc19333c5c300d7ac273e1580dc9350","label":"goharbor/harbor@85e7564"},"references":[{"type":"WEB","url":"https://github.com/goharbor/harbor/security/advisories/GHSA-prh4-vhfh-24mj"},{"type":"WEB","url":"https://github.com/goharbor/harbor/commit/85e756486fc19333c5c300d7ac273e1580dc9350"},{"type":"PACKAGE","url":"https://github.com/goharbor/harbor"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-04-08T05:18:55.793745Z"}}