Use of hard coded credentials in GoHarbor Harbor version 2.15.0 and below, allows attackers to use the default password and gain access to the web UI.
{
"cpes": [
"cpe:2.3:a:linuxfoundation:harbor:*:*:*:*:*:*:*:*"
],
"severity": "Critical"
}