AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2024-5891

MEDIUM · CVSS 4.2 EPSS 0.23%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2024-06-12 · Last synced 2026-08-04

CyberRota Analysis

This is a medium severity vulnerability with a CVSS score of 4.2. See the original NVD description below for full technical details.

CVE
CVE-2024-5891
Severity
MEDIUM
CVSS
4.2
EPSS
0.23%

Original NVD Description

A vulnerability was found in Quay. If an attacker can obtain the client ID for an application, they can use an OAuth token to authenticate despite not having access to the organization from which the application was created. This issue is limited to authentication and not authorization. However, in configurations where endpoints rely only on authentication, a user may authenticate to applications they otherwise have no access to.

Related CVEs

Other vulnerabilities affecting the same vendor(s)