Harbor write configuration payload to audit log when configuration change, the ldap_search_password and oidc_client_secret will be logged in the audit log without redacted
Harbor v2.15.0, v2.14.3, v2.13.5
Disable audit log configure event in Harbor Web Console: Go to Administration -> Configuration -> Enable Audit Log Event Type -> Uncheck "Update Configuration" and click "Save" Button.
{
"cwe_ids": [
"CWE-312",
"CWE-532"
],
"github_reviewed": true,
"github_reviewed_at": "2026-03-26T22:25:26Z",
"nvd_published_at": null,
"severity": "MODERATE"
}