mediumVulnerability

GHSA-prh4-vhfh-24mj

### Impact Harbor write configuration payload to audit log when configuration change, the ldap_search_password and oidc_client_secret will be logged in the audit log without redacted ### Patches Harbor v2.15.0, v2.14.3, v2.13.5 ### Workarounds Disable audit log configure event in Harbor Web Console: Go to Administration -> Configuration -> Enable Audit Log Event Type -> Uncheck "Update Configuration" and click "Save" Button.

Properties

ghsa_id
GHSA-prh4-vhfh-24mj
severity
medium
summary
Harbor: LDAP password and OIDC secret are not redacted in the audit log
cve_id
GHSA-prh4-vhfh-24mj
is_ghsa_only
true
ghsa_published
2026-03-26T22:25:26Z
source_url
https://github.com/advisories/GHSA-prh4-vhfh-24mj
ghsa_updated
2026-03-26T22:25:27Z

Related Entities (4)

AFFECTS (1)

[Software]go/github.com/goharbor/harbor

HAS_WEAKNESS (2)

[Weakness]Cleartext Storage of Sensitive Information
[Weakness]Insertion of Sensitive Information into Log File

REPORTED_BY (1)

[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph

GHSA-prh4-vhfh-24mj — Ninja Signal Threat Intelligence | Ninja Signal