Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2020-27831

Опубликовано: 27 мая 2021
Источник: nvd
CVSS3: 4.3
CVSS2: 4
EPSS Низкий

Описание

A flaw was found in Red Hat Quay, where it does not properly protect the authorization token when authorizing email addresses for repository email notifications. This flaw allows an attacker to add email addresses they do not own to repository notifications.

Ссылки

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:redhat:quay:*:*:*:*:*:*:*:*
Версия от 3.0.0 (включая) до 3.3.3 (исключая)

EPSS

Процентиль: 32%
0.00127
Низкий

4.3 Medium

CVSS3

4 Medium

CVSS2

Дефекты

CWE-284
CWE-522

Связанные уязвимости

CVSS3: 2.6
redhat
около 5 лет назад

A flaw was found in Red Hat Quay, where it does not properly protect the authorization token when authorizing email addresses for repository email notifications. This flaw allows an attacker to add email addresses they do not own to repository notifications.

CVSS3: 4.3
github
больше 3 лет назад

A flaw was found in Red Hat Quay, where it does not properly protect the authorization token when authorizing email addresses for repository email notifications. This flaw allows an attacker to add email addresses they do not own to repository notifications.

EPSS

Процентиль: 32%
0.00127
Низкий

4.3 Medium

CVSS3

4 Medium

CVSS2

Дефекты

CWE-284
CWE-522