Skip to main content

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Package: pkg:github/harness/harness

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

A vulnerability in Harness through version 3.3.0 allows authenticated users to bypass access control on the infrastructure provider read endpoint. This flaw enables retrieval of provider configurations from spaces the user does not belong to. Sensitive metadata exposed includes Docker endpoints, TLS certificate paths, and cloud project identifiers. The vulnerability has a CVSS score of 6.5, indicating a high severity impact on confidentiality without affecting integrity or availability.

Join the discussion
0

A vulnerability was determined in Harness up to 2.28.2. This vulnerability affects the function getAuthorizedSpaces of the file app/api/controller/gitspace/list_all.go of the component gitspaces Endpoint. Executing a manipulation can lead to authorization bypass. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through an issue report but has not responded yet.

Join the discussion

Showing 1 to 2 of 2 results

Filters:Package: pkg:github/harness/harness
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses