Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3mxm-3qx9-6gq2

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 4.3

Описание

A flaw was found in Red Hat Quay, where it does not properly protect the authorization token when authorizing email addresses for repository email notifications. This flaw allows an attacker to add email addresses they do not own to repository notifications.

A flaw was found in Red Hat Quay, where it does not properly protect the authorization token when authorizing email addresses for repository email notifications. This flaw allows an attacker to add email addresses they do not own to repository notifications.

EPSS

Процентиль: 32%
0.00127
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-284
CWE-522

Связанные уязвимости

CVSS3: 2.6
redhat
около 5 лет назад

A flaw was found in Red Hat Quay, where it does not properly protect the authorization token when authorizing email addresses for repository email notifications. This flaw allows an attacker to add email addresses they do not own to repository notifications.

CVSS3: 4.3
nvd
больше 4 лет назад

A flaw was found in Red Hat Quay, where it does not properly protect the authorization token when authorizing email addresses for repository email notifications. This flaw allows an attacker to add email addresses they do not own to repository notifications.

EPSS

Процентиль: 32%
0.00127
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-284
CWE-522