When Harbor is configured with OIDC authentication and users log in via a link outside the Harbor server, it might be vulnerable to an open redirect attack. This attack only involves the OIDC Harbor user, if the current Harbor instance is not configured with OIDC auth, the redirect_url doesn't exist and the Harbor instance is not vulnerable to the open redirect attack.
The following versions of Harbor are involved:
This Cyber News was published on www.tenable.com. Publication date: Mon, 03 Jun 2024 14:56:03 +0000