A flaw was found in Red Hat Quay, where it does not properly protect the authorization token when authorizing email addresses for repository email notifications. This flaw allows an attacker to add email addresses they do not own to repository notifications.
References
Link Resource
https://bugzilla.redhat.com/show_bug.cgi?id=1905758 Issue Tracking Vendor Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: redhat

Published: 2021-05-26T23:46:57

Updated: 2021-05-26T23:46:57

Reserved: 2020-10-27T00:00:00


Link: CVE-2020-27831

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2021-05-27T00:15:08.290

Modified: 2022-10-21T19:43:52.320


Link: CVE-2020-27831

JSON object: View

cve-icon Redhat Information

No data.