CVE-2020-27831

A flaw was found in Red Hat Quay, where it does not properly protect the authorization token when authorizing email addresses for repository email notifications. This flaw allows an attacker to add email addresses they do not own to repository notifications.
References
Link Resource
https://bugzilla.redhat.com/show_bug.cgi?id=1905758 Issue Tracking Vendor Advisory
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

cpe:2.3:a:redhat:quay:*:*:*:*:*:*:*:*

Information

Published : 2021-05-26 17:15

Updated : 2022-10-21 12:43


NVD link : CVE-2020-27831

Mitre link : CVE-2020-27831


JSON object : View

CWE
CWE-522

Insufficiently Protected Credentials

Advertisement

dedicated server usa

Products Affected

redhat

  • quay