An access control issue in Harbor v1.X.X to v2.5.3 allows attackers to access public and private image repositories without authentication. NOTE: the vendor's position is that this "is clearly described in the documentation as a feature."
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
3 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository contains a Python script (main.py) that automates the exploitation of misconfigured or vulnerable Harbor container registry instances (CVE-2022-46463). The script can enumerate all image repositories and tags by querying the Harbor API (supporting both v1 and v2 endpoints), obtain authentication tokens (if required), and download container images directly using HTTP requests (without using Docker). Downloaded images are automatically extracted to a local 'target' directory. The script is designed for use in red team operations or supply chain attacks where Harbor instances are exposed with weak or no access controls. The README provides detailed usage instructions and describes the attack workflow. The only code file is main.py, which contains all logic for enumeration, download, and extraction. The script requires the user to specify the target Harbor URL and optionally edit a results file to select which images to download. No hardcoded credentials or targets are present, but the script is ready for operational use against accessible Harbor registries.
This repository provides Python scripts (harbor.py and registry.py) to exploit unauthenticated access to Harbor and Docker Registry instances, specifically targeting CVE-2022-46463. The main script, harbor.py, interacts with the Harbor API to enumerate public images, list tags, retrieve build history, and download image layers. The registry.py script provides similar functionality for generic Docker Registry instances. Both scripts automate the process of extracting potentially sensitive information from public images, which may include secrets, credentials, or other confidential data inadvertently included in container images. The exploit leverages unauthenticated API endpoints exposed by misconfigured or vulnerable Harbor/Docker Registry servers. The repository also includes a README.md with usage instructions and references. The code is operational and can be used to extract real data from vulnerable targets.
This repository contains a proof-of-concept (POC) exploit for CVE-2022-46463, a vulnerability in VMware Harbor (a popular container registry) that allows unauthenticated users to enumerate repositories and pull container images via exposed API endpoints. The main file, 'cve-2022-46463.py', is a Python script that takes a Harbor base URL as input and performs the following actions: 1. Connects to the Harbor instance using the provided URL. 2. Calls the '/api/v2.0/search?q=/' endpoint to enumerate all available repositories. 3. For each repository, calls '/api/v2.0/projects/{project}/repositories/{name}/artifacts?page_size=100' to list all artifacts (container images/tags). 4. Constructs and outputs 'docker pull' commands for each artifact, allowing anyone to pull images without authentication. The script demonstrates the impact of the vulnerability by showing how an attacker can exfiltrate all container images from a vulnerable Harbor instance. The repository structure is simple, consisting of a README with usage instructions and the main exploit script. No fake or destructive actions are present; the script is focused on information disclosure and enumeration.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
1 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.