✉news TechnologyCybersecurity first seen 11 h ago, last 11 h ago, peak #37
SSRF Flaw in Harbor Webhooks Exposes Cloud Credentials
Original: SSRF in Harbor Webhooks: Any User Can Reach the Server’s Cloud Credentials
A security vulnerability has been disclosed in Harbor's webhook feature, allowing any authenticated user to trigger server-side request forgery that can reach metadata services holding the server's cloud credentials. The finding raises concerns for organizations running Harbor, the open-source container registry, as exposed cloud keys could lead to broader infrastructure compromise. Details on affected versions and fixes remain limited so far.
Why now: The disclosure of a cloud credential exposure risk in a widely used container registry is prompting security teams to check their deployments.
Evidence
API: https://socialmediatrends-api.osmike.com/v1/trends/1350357