First published: Wed Dec 09 2020(Updated: )
A flaw was found in Red Hat Quay, where it has a persistent Cross-site Scripting (XSS) vulnerability when displaying a repository's notification. This flaw allows an attacker to trick a user into performing a malicious action to impersonate the target user. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/quay | <3.3.2 | 3.3.2 |
Redhat Quay | >=3.0.0<3.3.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-27832 is a persistent Cross-site Scripting (XSS) vulnerability in Red Hat Quay.
CVE-2020-27832 allows an attacker to trick a user into performing a malicious action by impersonating the target user.
CVE-2020-27832 has a severity rating of critical with a score of 9.
To fix CVE-2020-27832, update to version 3.3.2 of Red Hat Quay.
You can find more information about CVE-2020-27832 on GitHub, Red Hat's issue tracker, and Red Hat's errata page.