-
Bug
-
Resolution: Not a Bug
-
Major
-
None
-
None
-
None
-
False
-
-
False
-
-
Description:
Readonly super user can see regular user's tag Security report/Packages
Quay:
stable-3-16-v4-19
quay.io/redhat-user-workloads/quay-eng-tenant/stable-3-16-v4-19@sha256:541c7f45baf8b1de998c7f80c601bbfb528d6c3ffd49dcfa6ca99a369c1682f7
Steps:
1, Login with regular common user: user1, create user1org/user1repo, push tag ubuntu
2, Click the tag name -> Security report/Packages, can see tag vuln scan result

3, Login with Global Readonly Superuser, go to same path user1org/user1repo/tag/ubuntu
4, Click the tag name -> Security report/Packages
Result:
Looping, no value returned
