Location Research Breakthrough Possible @S-Logix pro@slogix.in

Measuring Anonymous Container Image Registry Access Risk in Harbor Deployments Through Vulnerability Assessment and Remediation Validation

Description

Organizations use Harbor as a container image registry for storing, managing, and distributing container images used by applications and services.

Harbor projects can be configured with different visibility and access-control settings. If a project is configured for public access, container images within that project may be retrievable without authenticated Harbor credentials.

In this use case, a controlled Harbor container registry is deployed on Ubuntu Linux inside an isolated VirtualBox laboratory. Kali Linux is used as the controlled vulnerability-assessment system.

The application used inside the container image is OWASP NodeGoat. NodeGoat is packaged as a container image and stored in the Harbor repository. Harbor is the target registry platform, while NodeGoat provides the controlled application artifact being assessed.

A controlled anonymous container image registry access assessment is performed to determine whether an unauthenticated user can discover and retrieve the NodeGoat container image.

Trivy is used to assess vulnerabilities in the NodeGoat container image. Wazuh monitors relevant Ubuntu and Harbor activity, while OpenSearch supports centralized investigation and correlation.

The identified exposure is risk-prioritized, remediated by restricting project access, and then retested to validate the remediation.

The complete vulnerability-management workflow is: Harbor Deployment → Project/Repository Discovery → Anonymous Access Assessment → Registry Exposure Identification → Container Artifact Enumeration → Vulnerability Scanning → Risk Prioritization → Remediation Planning → Project Access Restriction → Vulnerable Artifact Protection → Post-Remediation Access Testing → Security Monitoring → Evidence Correlation → Remediation Validation.

Existing Security Problem

Application: Harbor

Harbor is the target container image registry application in this use case. It provides centralized storage, management, and distribution of container images.

Existing Problem:

Harbor projects can be configured as public or private. A public project may allow users to pull container images without authentication. If a container image containing vulnerable application components is exposed through an anonymously accessible project, an unauthorized user may be able to retrieve the container artifact and identify vulnerable components. In this use case, OWASP NodeGoat is packaged as the container image and stored in the Harbor repository.

The security problem is therefore:

Harbor Public Project → Anonymous Access → NodeGoat Repository → NodeGoat Container Image → Container Artifact Exposure → Known Vulnerabilities → Security Risk

The assessment validates anonymous access, identifies exposed artifacts, scans the exposed NodeGoat image, prioritizes the identified risk, applies access-control remediation, and performs post-remediation validation.

Attack

Specific Attack: Anonymous Container Image Registry Access

The attack scenario focuses on unauthorized retrieval of a container image from a Harbor project that has been intentionally configured as publicly accessible within the authorized laboratory. The assessment validates whether the Harbor project permits unauthenticated registry access. Kali Linux is used to identify the Harbor registry, discover the publicly accessible project and repository, and attempt to retrieve the NodeGoat container image without authentication.

Attack Behavior:
Kali Linux
→
Harbor Discovery
→
Public Project Discovery
→
Repository Enumeration
→
Unauthenticated Access
→
Image Metadata Retrieval
→
NodeGoat Image Pull
→
Exposed Artifact Identification
→
Vulnerability Scanning
→
Risk Prioritization
→
Access-Control Remediation
→
Anonymous Access Retest
→
Access Denied

Security Concept

Anonymous Registry Exposure Assessment, Vulnerability-Based Risk Prioritization, and Remediation Validation:

Anonymous registry exposure assessment determines whether a Harbor project or repository can be accessed without authenticated credentials. Vulnerability-based risk prioritization considers both the accessibility of the container artifact and the vulnerabilities identified within it. Remediation validation confirms that access restrictions are effective after the required changes are applied.

The assessment validates Harbor project visibility, repository discovery, image metadata access, and container image retrieval. Trivy scans the exposed NodeGoat container image to identify known vulnerabilities in the application and its software components. The findings are considered together with the anonymous exposure context to prioritize remediation. The Harbor project is then changed from public to private, and the original anonymous-access assessment is repeated to verify that unauthorized access is rejected while authorized access remains available.

The secure processing flow is:

Harbor Project Visibility
→
Anonymous Access Assessment
→
NodeGoat Image Exposure
→
Vulnerability Assessment
→
Risk Prioritization
→
Access-Control Remediation
→
Post-Remediation Validation

Defensive Mechanism

Harbor Project Access-Control Assessment

Harbor project visibility and access-control settings are reviewed.

Purpose

Establish whether the project permits unintended anonymous access.

Anonymous Access Validation

Unauthenticated registry requests are tested against the controlled Harbor project.

Purpose

Identify whether container artifacts can be accessed without authentication.

Repository Exposure Assessment

Repositories and available container artifacts within the accessible project are identified.

Purpose

Establish the scope of container image exposure.

Container Artifact Assessment

The exposed NodeGoat container image is identified and assessed.

Purpose

Determine which container artifact is accessible through the exposed project.

Container Vulnerability Scanning

Trivy scans the exposed NodeGoat image for known vulnerabilities.

Purpose

Identify vulnerable software components within the exposed container artifact.

Severity-Based Prioritization

Identified vulnerabilities are reviewed according to their severity and exposure context.

Purpose

Establish the appropriate remediation priority.

Project Privacy Remediation

The publicly accessible Harbor project is changed to private access.

Purpose

Prevent unauthorized users from retrieving the container image.

Vulnerable Artifact Protection

Harbor vulnerability-protection controls are reviewed and configured according to the defined security policy.

Purpose

Prevent vulnerable container artifacts from being distributed when policy requires blocking them.

Post-Remediation Validation

The same anonymous-access assessment is repeated after remediation.

Purpose

Confirm that the identified exposure has been successfully remediated.

Security Monitoring

Wazuh monitors relevant Harbor and Ubuntu security activity.

Purpose

Provide visibility into registry and system security events.

Security Investigation

OpenSearch centralizes and correlates the collected security events.

Purpose

Support investigation and evidence validation.

Security Tools

Target Application: Harbor

Harbor is the application being assessed.

Purpose
  • Provide the container image registry environment.
  • Host the controlled project and repository.
  • Store the NodeGoat container image.
  • Configure project visibility.
  • Apply access-control remediation.
  • Validate anonymous and authenticated access.

Application Inside Container Image: OWASP NodeGoat

OWASP NodeGoat is the application packaged inside the container image.

Purpose
  • Provide the controlled application artifact.
  • Store the application image in Harbor.
  • Provide the container image for vulnerability assessment.
  • Validate image retrieval through Harbor.
  • Provide the artifact for Trivy scanning.

Vulnerability Scanning Tool: Trivy

Trivy is used to scan the NodeGoat container image.

Purpose
  • Identify vulnerabilities.
  • Identify vulnerable packages.
  • Determine vulnerability severity.
  • Support risk prioritization.
  • Validate vulnerability findings after remediation.

Security Testing Platform: Kali Linux

Kali Linux provides the controlled vulnerability-assessment environment.

Purpose
  • Perform Harbor discovery.
  • Identify publicly accessible projects.
  • Test anonymous repository access.
  • Attempt controlled image retrieval.
  • Perform post-remediation validation.

Container Platform: Docker

Docker is used to interact with the NodeGoat container image.

Purpose
  • Build or obtain the NodeGoat image.
  • Tag the image.
  • Push the image to Harbor.
  • Pull the image during the assessment.
  • Validate authorized image access.

Registry Interface: Harbor Registry API / OCI Interface

The registry interface is used to interact with Harbor repositories and container artifacts.

Purpose
  • Validate registry accessibility.
  • Identify repository information.
  • Retrieve image metadata.
  • Validate anonymous registry requests.

Target Operating System: Ubuntu Linux

Ubuntu provides the controlled Harbor server environment.

Purpose
  • Host Harbor.
  • Store container registry data.
  • Support Docker and Harbor services.
  • Generate system activity for security monitoring.

Security Monitoring Tool: Wazuh

Wazuh monitors relevant Harbor, Docker, and Ubuntu activity.

Purpose
  • Collect security events.
  • Monitor relevant system activity.
  • Provide security-event visibility.
  • Support assessment evidence collection.

Security Investigation Platform: OpenSearch

OpenSearch provides centralized security-event investigation.

Purpose
  • Receive relevant security events.
  • Search collected events.
  • Correlate registry activity.
  • Support investigation and evidence validation.

Virtualization Platform: VirtualBox

VirtualBox provides the isolated laboratory environment.

Purpose
  • Host Ubuntu.
  • Host Kali Linux.
  • Provide controlled network communication.
  • Isolate the vulnerability assessment.

Process

STEP 01

Step 1: Prepare the Isolated Vulnerability-Management Laboratory

  • Create an isolated cybersecurity laboratory using VirtualBox.
  • Configure Ubuntu as the Harbor server.
  • Configure Kali Linux as the vulnerability-assessment system.
  • Establish controlled network communication between the virtual machines.
  • Verify connectivity between the systems.
  • Confirm that testing is restricted to the authorized laboratory environment.
Tools: VirtualBox + Ubuntu Linux + Kali Linux
STEP 02

Step 2: Deploy Harbor

  • Install and configure Harbor on the Ubuntu environment.
  • Verify that the Harbor portal is operational.
  • Verify that the Harbor registry service is operational.
  • Confirm that Harbor can store and distribute container images.
Tools: Harbor + Ubuntu Linux
STEP 03

Step 3: Configure Vulnerability Scanning

  • Configure Trivy as the Harbor vulnerability-scanning capability.
  • Verify that container image vulnerability scanning is available.
  • Confirm that vulnerability results can be generated for stored container images.
Tools: Harbor + Trivy
STEP 04

Step 4: Create the Controlled Harbor Project and Repository

  • Create the controlled Harbor project.
  • Create the NodeGoat repository inside the project.
  • Prepare the OWASP NodeGoat container image.
  • Tag the image as `nodegoat:v1`.
  • Push the NodeGoat container image into the Harbor repository.
  • Verify that the image is available in Harbor.
Tools: Harbor + Docker + OWASP NodeGoat
STEP 05

Step 5: Establish the Authenticated Access Baseline

  • Create an authorized Harbor user.
  • Authenticate to Harbor using the authorized account.
  • Access the NodeGoat repository using the authorized account.
  • Retrieve the NodeGoat image using authenticated access.
  • Record the normal authenticated-access behavior.
Tools: Harbor + Docker
STEP 06

Step 6: Configure the Public Project Condition

  • Configure the controlled Harbor project as publicly accessible.
  • Verify the project visibility configuration.
  • Confirm that the NodeGoat repository is available within the project.
  • Record the public project configuration before assessment.
Tools: Harbor
STEP 07

Step 7: Perform Anonymous Project Discovery

  • From Kali Linux, identify the Harbor registry.
  • Access the Harbor registry without using Harbor credentials.
  • Discover the publicly accessible Harbor project.
  • Record the accessible project information.
  • Preserve the assessment evidence.
Tools: Kali Linux + Harbor Registry API
STEP 08

Step 8: Validate Anonymous Repository Access

  • Identify the NodeGoat repository within the publicly accessible project.
  • Attempt to access the repository without authentication.
  • Review the Harbor registry response.
  • Determine whether repository information is accessible anonymously.
  • Record the result of the anonymous repository-access test.
Tools: Kali Linux + Harbor Registry API / OCI Interface
STEP 09

Step 9: Perform Anonymous Image Pull

  • Attempt to retrieve the NodeGoat image without Harbor authentication.
  • Use Docker to pull the image from the publicly accessible Harbor repository.
  • Verify whether the image download is successful.
  • Record the anonymous image-pull result.
  • Preserve the relevant assessment evidence.
Tools: Kali Linux + Docker + Harbor
STEP 10

Step 10: Enumerate the Exposed Container Artifact

  • Identify the accessible NodeGoat image tag.
  • Identify the available image metadata.
  • Confirm that the NodeGoat container image is exposed through anonymous registry access.
  • Record the exposed container artifact details.
  • Preserve the relevant assessment evidence.
Tools: Docker + Harbor Registry API
STEP 11

Step 11: Perform Container Vulnerability Scanning

  • Identify the NodeGoat container image available in Harbor.
  • Scan the NodeGoat image using Trivy.
  • Identify the vulnerable packages and software components.
  • Record the reported vulnerability identifiers.
  • Record the reported vulnerability severity levels.
  • Preserve the Trivy assessment results.
Tools: Trivy + Harbor
STEP 12

Step 12: Assess and Prioritize the Identified Risk

  • Review the anonymous accessibility of the NodeGoat container image.
  • Review the vulnerabilities identified by Trivy.
  • Correlate the container exposure with vulnerability severity.
  • Determine the security impact of the exposed artifact.
  • Prioritize the identified finding for remediation.
  • Document the risk-prioritization result.
Tools: Trivy + Harbor
STEP 13

Step 13: Apply Project Access-Control Remediation

  • Change the Harbor project visibility from public to private.
  • Verify the updated project visibility configuration.
  • Confirm that anonymous project access is no longer permitted.
  • Record the remediation configuration.
  • Preserve the remediation evidence.
Tools: Harbor
STEP 14

Step 14: Configure Vulnerability Protection

  • Review the Harbor vulnerability-protection configuration.
  • Configure the required vulnerability policy according to the defined security policy.
  • Apply the required protection for vulnerable container artifacts.
  • Verify the resulting vulnerability-protection configuration.
  • Record the configured policy.
Tools: Harbor + Trivy
STEP 15

Step 15: Perform Post-Remediation Anonymous Access Testing

  • Repeat the original anonymous-access assessment from Kali Linux.
  • Attempt to access the Harbor project without authentication.
  • Attempt to access the NodeGoat repository without authentication.
  • Attempt to retrieve the NodeGoat image without credentials.
  • Verify that anonymous access is rejected.
  • Record the post-remediation assessment result.
Tools: Kali Linux + Harbor Registry API + Docker
STEP 16

Step 16: Validate Authorized Access After Remediation

  • Authenticate to Harbor using the authorized user account.
  • Access the private NodeGoat repository.
  • Retrieve the NodeGoat image using authorized credentials.
  • Verify that authorized access remains available.
  • Record the successful authorized-access result.
Tools: Harbor + Docker
STEP 17

Step 17: Collect Security Monitoring Evidence

  • Collect relevant Harbor security events using Wazuh.
  • Collect relevant Docker and Ubuntu security events.
  • Review events generated during anonymous-access testing.
  • Review events generated during remediation activities.
  • Preserve the relevant monitoring evidence.
Tools: Wazuh + Ubuntu Linux
STEP 18

Step 18: Perform Centralized Security Investigation

  • Forward relevant Wazuh events to OpenSearch.
  • Search for Harbor registry-access activity.
  • Correlate anonymous-access events with system activity.
  • Review events associated with the remediation activity.
  • Validate the assessment timeline using collected security evidence.
  • Preserve the investigation results.
Tools: Wazuh + OpenSearch
STEP 19

Step 19: Perform Final Vulnerability Assessment and Remediation Validation

  • Compare the pre-remediation and post-remediation assessment results.
  • Confirm that anonymous access to the NodeGoat image is no longer permitted.
  • Confirm that authorized users can still access the required image.
  • Review the Trivy vulnerability findings.
  • Review the Wazuh and OpenSearch security evidence.
  • Validate the complete remediation result.
  • Document the final vulnerability-management assessment.
Tools: Harbor + Trivy + Wazuh + OpenSearch + Kali Linux

Outcome

  1. A controlled Harbor deployment was established in an isolated laboratory.
  2. Anonymous access to the Harbor project was assessed.
  3. Anonymous retrieval of the NodeGoat container image was validated.
  4. The exposed NodeGoat image was assessed using Trivy.
  5. Identified vulnerabilities and exposure were risk-prioritized.
  6. The Harbor project was changed from public to private.
  7. Vulnerability-protection controls were configured according to the defined security policy.
  8. Post-remediation testing confirmed that anonymous image access was rejected while authorized access remained available.
  9. Wazuh and OpenSearch provided security monitoring and investigation evidence.
  10. The complete vulnerability-management lifecycle was demonstrated from exposure identification through vulnerability assessment, remediation, and final validation.