First published: Wed Jul 01 2020(Updated: )
An information disclosure vulnerability was found in Red Hat Quay in versions before 3.3.1. This flaw allows an attacker who can create a build trigger in a repository, to disclose the names of robot accounts and the existence of private repositories within any namespace.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Redhat Quay | <3.3.1 | |
redhat/quay | <3.3.1 | 3.3.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2020-14313.
The severity of CVE-2020-14313 is medium.
Red Hat Quay versions before 3.3.1 are affected by CVE-2020-14313.
An attacker who can create a build trigger in a repository can exploit CVE-2020-14313 to disclose the names of robot accounts and the existence of private repositories within any namespace.
To fix CVE-2020-14313, upgrade Red Hat Quay to version 3.3.1 or later.