Data Exposure Vulnerability in Red Hat Quay
CVE-2026-74242
5.3MEDIUM
What is CVE-2026-74242?
A flaw exists in Red Hat Quay that permits an administrator with knowledge of a notification's Universally Unique Identifier (UUID) to access the notification configuration. This includes the ability to view sensitive information such as webhook URLs, Slack tokens, and email addresses. Additionally, this vulnerability enables the administrator to trigger test notifications for other repositories, which may result in unauthorized information disclosure and potential misuse of notification services.
References
CVSS V3.1
Score:
5.3
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Red Hat would like to thank meifukun (https://github.com/meifukun) for reporting this issue.