CVE-2020-14313
published 2020-08-11CVE-2020-14313: An information disclosure vulnerability was found in Red Hat Quay in versions before 3.3.1. This flaw allows an attacker who can create a build trigger in a…
PriorityP419medium4.3CVSS 3.1
AVNACLPRLUINSUCLINAN
EPSS
0.87%
54.7th percentile
An information disclosure vulnerability was found in Red Hat Quay in versions before 3.3.1. This flaw allows an attacker who can create a build trigger in a repository, to disclose the names of robot accounts and the existence of private repositories within any namespace.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | quay | < 3.3.1 | 3.3.1 |
| redhat | quay | — | — |
CVSS provenance
nvdv3.14.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
quay: build triggers can disclose robot account names and existence of private repos within namespaces
vendor_redhat·2020-07-06·CVSS 4.3
CVE-2020-14313 [MEDIUM] CWE-200 quay: build triggers can disclose robot account names and existence of private repos within namespaces
quay: build triggers can disclose robot account names and existence of private repos within namespaces
An information disclosure vulnerability was found in Red Hat Quay in versions before 3.3.1. This flaw allows an attacker who can create a build trigger in a repository, to disclose the names of robot accounts and the existence of private repositories within any namespace.
An information disclosure vulnerability was found in Red Hat Quay. This flaw allows an attacker who can create a build trigger in a repository, to disclose the names of robot accounts and the existence of private repositories within any namespace.
Package: quay (Red Hat Quay 3) - Affected
GHSA
GHSA-qp9w-fqwx-r4j3: An information disclosure vulnerability was found in Red Hat Quay in versions before 3
ghsa_unreviewed·2022-05-24
CVE-2020-14313 [MEDIUM] CWE-200 GHSA-qp9w-fqwx-r4j3: An information disclosure vulnerability was found in Red Hat Quay in versions before 3
An information disclosure vulnerability was found in Red Hat Quay in versions before 3.3.1. This flaw allows an attacker who can create a build trigger in a repository, to disclose the names of robot accounts and the existence of private repositories within any namespace.
No detection rules found.
No public exploits indexed.
2020-08-11
Published