SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2020-14313

An information disclosure vulnerability was found in Red Hat Quay in versions before 3.3.1.

MEDIUM 4.3EPSS 0.87%

Does this matter?

Lower severity and a low EPSS score (0.87%). Track it; it rarely justifies an emergency change on its own.

Description

An information disclosure vulnerability was found in Red Hat Quay in versions before 3.3.1. This flaw allows an attacker who can create a build trigger in a repository, to disclose the names of robot accounts and the existence of private repositories within any namespace.

CVSS 3.1
4.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
EPSS
0.87% probability · 57th percentile
CISA KEV
Not listed
Affected
redhat/quay
Source
secalert@redhat.com

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.