An information disclosure vulnerability was found in Red Hat Quay in versions before 3.3.1. This flaw allows an attacker who can create a build trigger in a repository, to disclose the names of robot accounts and the existence of private repositories within any namespace.
Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-14313
Reference (s):
- https://bugzilla.redhat.com/show_bug.cgi?id=1853026
- URL: https://bugzilla.redhat.com/show_bug.cgi?id=1853026

