An information disclosure vulnerability was found in Red Hat Quay in versions before 3.3.1. This flaw allows an attacker who can create a build trigger in a repository, to disclose the names of robot accounts and the existence of private repositories within any namespace.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Quay | Redhat | * | 3.3.1 (excluding) |
| Red Hat Quay 3 | RedHat | quay-bridge-operator-container | * |
| Red Hat Quay 3 | RedHat | quay-bridge-operator-metadata-container | * |
| Red Hat Quay 3 | RedHat | quay-cso-operator-container | * |
| Red Hat Quay 3 | RedHat | quay-cso-operator-metadata-container | * |
| Red Hat Quay 3 | RedHat | quay-operator-bundle-container | * |
| Red Hat Quay 3 | RedHat | quay-setup-operator-container | * |