CVE-2020-27831

A flaw was found in Red Hat Quay, where it does not properly protect the authorization token when authorizing email addresses for repository email notifications. This flaw allows an attacker to add email addresses they do not own to repository notifications.
References
Link Resource
https://bugzilla.redhat.com/show_bug.cgi?id=1905758 Issue Tracking Vendor Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=1905758 Issue Tracking Vendor Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:redhat:quay:*:*:*:*:*:*:*:*

History

21 Nov 2024, 05:21

Type Values Removed Values Added
References () https://bugzilla.redhat.com/show_bug.cgi?id=1905758 - Issue Tracking, Vendor Advisory () https://bugzilla.redhat.com/show_bug.cgi?id=1905758 - Issue Tracking, Vendor Advisory

Information

Published : 2021-05-27 00:15

Updated : 2024-11-21 05:21


NVD link : CVE-2020-27831

Mitre link : CVE-2020-27831

CVE.ORG link : CVE-2020-27831


JSON object : View

Products Affected

redhat

  • quay
CWE
CWE-284

Improper Access Control

CWE-522

Insufficiently Protected Credentials