RHSA-2020:3525: Moderate: Red Hat Quay v3.3.1 security update
Quay 3.3.1 release, including:Security Fix(es): quay: build triggers can disclose robot account names and existence of private repos within namespaces (CVE-2020-14313) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.Bug Fix(es): Quay 3.3.1 release (BZ#1844197)
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2020:3525?
The severity of RHSA-2020:3525 is classified as moderate.
What is the main vulnerability addressed in RHSA-2020:3525?
RHSA-2020:3525 addresses a vulnerability that allows build triggers to disclose robot account names and the existence of private repositories within namespaces (CVE-2020-14313).
How do I fix RHSA-2020:3525?
To fix RHSA-2020:3525, you should upgrade to the latest version of Red Hat Quay that resolves this security issue.
What impact does RHSA-2020:3525 have on users?
RHSA-2020:3525 potentially exposes sensitive information about robot accounts and private repositories, affecting user security.
Who is affected by RHSA-2020:3525?
Users of Red Hat Quay version 3.3.1 and prior are affected by the vulnerabilities addressed in RHSA-2020:3525.