SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2020-27831

This flaw allows an attacker to add email addresses they do not own to repository notifications.

MEDIUM 4.3EPSS 0.55%

Does this matter?

Lower severity and a low EPSS score (0.55%). Track it; it rarely justifies an emergency change on its own.

Description

A flaw was found in Red Hat Quay, where it does not properly protect the authorization token when authorizing email addresses for repository email notifications. This flaw allows an attacker to add email addresses they do not own to repository notifications.

CVSS 3.1
4.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
EPSS
0.55% probability · 44th percentile
CISA KEV
Not listed
Weakness
CWE-284, CWE-522
Affected
redhat/quay
Source
secalert@redhat.com

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.