CVE-2020-27832: XSS
A flaw was found in Red Hat Quay, where it has a persistent Cross-site Scripting (XSS) vulnerability when displaying a repository's notification. This flaw allows an attacker to trick a user into performing a malicious action to impersonate the target user. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.
Other sources
Red Hat Quay has a persistent XSS vulnerability when displaying a repositories email notification. An attacker who can trick a user into performing a malicious action can use this flaw to impersonate the target user.
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-27832?
CVE-2020-27832 is a persistent Cross-site Scripting (XSS) vulnerability in Red Hat Quay.
How does CVE-2020-27832 affect Red Hat Quay?
CVE-2020-27832 allows an attacker to trick a user into performing a malicious action by impersonating the target user.
What is the severity of CVE-2020-27832?
CVE-2020-27832 has a severity rating of critical with a score of 9.
How can I fix CVE-2020-27832 in Red Hat Quay?
To fix CVE-2020-27832, update to version 3.3.2 of Red Hat Quay.
Where can I find more information about CVE-2020-27832?
You can find more information about CVE-2020-27832 on GitHub, Red Hat's issue tracker, and Red Hat's errata page.