Harbor: LDAP password and OIDC secret are not redacted in the audit log
Package
Affected versions
>= 2.13.0, < 2.13.5
>= 2.14.0, < 2.14.3
Patched versions
2.13.5
2.14.3
Description
Published to the GitHub Advisory Database
Mar 26, 2026
Reviewed
Mar 26, 2026
Last updated
Mar 26, 2026
Impact
Harbor write configuration payload to audit log when configuration change, the ldap_search_password and oidc_client_secret will be logged in the audit log without redacted
Patches
Harbor v2.15.0, v2.14.3, v2.13.5
Workarounds
Disable audit log configure event in Harbor Web Console: Go to Administration -> Configuration -> Enable Audit Log Event Type -> Uncheck "Update Configuration" and click "Save" Button.
References