Harbor Project Access-Control Assessment
Harbor project visibility and access-control settings are reviewed.
Establish whether the project permits unintended anonymous access.
Organizations use Harbor as a container image registry for storing, managing, and distributing container images used by applications and services.
Harbor projects can be configured with different visibility and access-control settings. If a project is configured for public access, container images within that project may be retrievable without authenticated Harbor credentials.
In this use case, a controlled Harbor container registry is deployed on Ubuntu Linux inside an isolated VirtualBox laboratory. Kali Linux is used as the controlled vulnerability-assessment system.
The application used inside the container image is OWASP NodeGoat. NodeGoat is packaged as a container image and stored in the Harbor repository. Harbor is the target registry platform, while NodeGoat provides the controlled application artifact being assessed.
A controlled anonymous container image registry access assessment is performed to determine whether an unauthenticated user can discover and retrieve the NodeGoat container image.
Trivy is used to assess vulnerabilities in the NodeGoat container image. Wazuh monitors relevant Ubuntu and Harbor activity, while OpenSearch supports centralized investigation and correlation.
The identified exposure is risk-prioritized, remediated by restricting project access, and then retested to validate the remediation.
The complete vulnerability-management workflow is: Harbor Deployment → Project/Repository Discovery → Anonymous Access Assessment → Registry Exposure Identification → Container Artifact Enumeration → Vulnerability Scanning → Risk Prioritization → Remediation Planning → Project Access Restriction → Vulnerable Artifact Protection → Post-Remediation Access Testing → Security Monitoring → Evidence Correlation → Remediation Validation.
Harbor is the target container image registry application in this use case. It provides centralized storage, management, and distribution of container images.
Harbor projects can be configured as public or private. A public project may allow users to pull container images without authentication. If a container image containing vulnerable application components is exposed through an anonymously accessible project, an unauthorized user may be able to retrieve the container artifact and identify vulnerable components. In this use case, OWASP NodeGoat is packaged as the container image and stored in the Harbor repository.
The security problem is therefore:
The assessment validates anonymous access, identifies exposed artifacts, scans the exposed NodeGoat image, prioritizes the identified risk, applies access-control remediation, and performs post-remediation validation.
The attack scenario focuses on unauthorized retrieval of a container image from a Harbor project that has been intentionally configured as publicly accessible within the authorized laboratory. The assessment validates whether the Harbor project permits unauthenticated registry access. Kali Linux is used to identify the Harbor registry, discover the publicly accessible project and repository, and attempt to retrieve the NodeGoat container image without authentication.
Anonymous registry exposure assessment determines whether a Harbor project or repository can be accessed without authenticated credentials. Vulnerability-based risk prioritization considers both the accessibility of the container artifact and the vulnerabilities identified within it. Remediation validation confirms that access restrictions are effective after the required changes are applied.
The assessment validates Harbor project visibility, repository discovery, image metadata access, and container image retrieval. Trivy scans the exposed NodeGoat container image to identify known vulnerabilities in the application and its software components. The findings are considered together with the anonymous exposure context to prioritize remediation. The Harbor project is then changed from public to private, and the original anonymous-access assessment is repeated to verify that unauthorized access is rejected while authorized access remains available.
The secure processing flow is:
Harbor project visibility and access-control settings are reviewed.
Establish whether the project permits unintended anonymous access.
Unauthenticated registry requests are tested against the controlled Harbor project.
Identify whether container artifacts can be accessed without authentication.
Repositories and available container artifacts within the accessible project are identified.
Establish the scope of container image exposure.
The exposed NodeGoat container image is identified and assessed.
Determine which container artifact is accessible through the exposed project.
Trivy scans the exposed NodeGoat image for known vulnerabilities.
Identify vulnerable software components within the exposed container artifact.
Identified vulnerabilities are reviewed according to their severity and exposure context.
Establish the appropriate remediation priority.
The publicly accessible Harbor project is changed to private access.
Prevent unauthorized users from retrieving the container image.
Harbor vulnerability-protection controls are reviewed and configured according to the defined security policy.
Prevent vulnerable container artifacts from being distributed when policy requires blocking them.
The same anonymous-access assessment is repeated after remediation.
Confirm that the identified exposure has been successfully remediated.
Wazuh monitors relevant Harbor and Ubuntu security activity.
Provide visibility into registry and system security events.
OpenSearch centralizes and correlates the collected security events.
Support investigation and evidence validation.
Harbor is the application being assessed.
OWASP NodeGoat is the application packaged inside the container image.
Trivy is used to scan the NodeGoat container image.
Kali Linux provides the controlled vulnerability-assessment environment.
Docker is used to interact with the NodeGoat container image.
The registry interface is used to interact with Harbor repositories and container artifacts.
Ubuntu provides the controlled Harbor server environment.
Wazuh monitors relevant Harbor, Docker, and Ubuntu activity.
OpenSearch provides centralized security-event investigation.
VirtualBox provides the isolated laboratory environment.