CVE-2020-27831

A flaw was found in Red Hat Quay, where it does not properly protect the authorization token when authorizing email addresses for repository email notifications. This flaw allows an attacker to add email addresses they do not own to repository notifications.
References
Link Resource
https://bugzilla.redhat.com/show_bug.cgi?id=1905758 Issue Tracking Vendor Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:redhat:quay:*:*:*:*:*:*:*:*

History

21 Oct 2022, 19:43

Type Values Removed Values Added
CWE CWE-284 CWE-522

03 Jun 2021, 19:19

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : 4.0
v3 : 4.3
References (MISC) https://bugzilla.redhat.com/show_bug.cgi?id=1905758 - (MISC) https://bugzilla.redhat.com/show_bug.cgi?id=1905758 - Issue Tracking, Vendor Advisory
CPE cpe:2.3:a:redhat:quay:*:*:*:*:*:*:*:*

27 May 2021, 02:11

Type Values Removed Values Added
CWE CWE-284

27 May 2021, 00:15

Type Values Removed Values Added
New CVE

Information

Published : 2021-05-27 00:15

Updated : 2023-12-10 13:55


NVD link : CVE-2020-27831

Mitre link : CVE-2020-27831

CVE.ORG link : CVE-2020-27831


JSON object : View

Products Affected

redhat

  • quay
CWE
CWE-522

Insufficiently Protected Credentials

CWE-284

Improper Access Control