Harbor 1.9.* 1.10.* and 2.0.* allows Exposure of Sensitive Information to an Unauthorized Actor.
https://github.com/advisories/GHSA-q9p8-33wc-h432
https://www.cybereagle.io/blog/cve-2020-13794/
https://github.com/goharbor/harbor/security/advisories/GHSA-q9p8-33wc-h432