PT-2021-11422 · Red Hat · Red Hat Quay

Published

2021-05-26

·

Updated

2022-10-21

·

CVE-2020-27831

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions: Red Hat Quay (affected versions not specified)
Description: A flaw was found in Red Hat Quay, where it does not properly protect the authorization token when authorizing email addresses for repository email notifications. This flaw allows an attacker to add email addresses they do not own to repository notifications.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Access Control

Insufficiently Protected Credentials

Weakness Enumeration

Related Identifiers

CVE-2020-27831

Affected Products

Red Hat Quay