An information disclosure vulnerability was found in Red Hat Quay in versions before 3.3.1. This flaw allows an attacker who can create a build trigger in a repository, to disclose the names of robot accounts and the existence of private repositories within any namespace.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Quay | Redhat | * | 3.3.1 (excluding) |
Red Hat Quay 3 | RedHat | quay-bridge-operator-container | * |
Red Hat Quay 3 | RedHat | quay-bridge-operator-metadata-container | * |
Red Hat Quay 3 | RedHat | quay-cso-operator-container | * |
Red Hat Quay 3 | RedHat | quay-cso-operator-metadata-container | * |
Red Hat Quay 3 | RedHat | quay-operator-bundle-container | * |
Red Hat Quay 3 | RedHat | quay-setup-operator-container | * |