Impact
The vulnerability is an IDOR that allows an administrator of any repository to discover and read the configuration of a notification belonging to another repository by guessing or knowing the notification’s UUID. The discovered data can include webhook URLs, Slack tokens, and email addresses, and the attacker can also trigger test notifications for that other repository. These capabilities expose sensitive information and could be abused to compromise downstream services if the credentials or callbacks are actionable.
Affected Systems
Red Hat Quay 3 and Red Hat OpenShift Update Service are affected. No specific version range is listed in the CNA data, so all installations of these products may be vulnerable until a vendor patch is applied.
Risk and Exploitability
The CVSS score is 5.3, indicating a moderate impact. EPSS is not available and the vulnerability is not listed in CISA KEV, suggesting no known widespread exploitation at the time of analysis. The likely attack vector requires local administrative access to a repository; an attacker who can impersonate or guess a UUID can read or execute notification actions. The absence of an official workaround means the risk remains until a vendor fix is released.
OpenCVE Enrichment