Red Hat Quay vulnerabilities
2 known vulnerabilities affecting red_hat/quay.
Total CVEs
2
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH1MEDIUM1
Vulnerabilities
Page 1 of 1
CVE-2019-3864HIGHCVSS 8.8vall quay-2 versions before quay-3.0.02020-01-21
CVE-2019-3864 [HIGH] CWE-352 CVE-2019-3864: A vulnerability was discovered in all quay-2 versions before quay-3.0.0, in the Quay web GUI where P
A vulnerability was discovered in all quay-2 versions before quay-3.0.0, in the Quay web GUI where POST requests include a specific parameter which is used as a CSRF token. The token is not refreshed for every request or when a user logged out and in again. An attacker could use a leaked token to gain access to the system using the user's account.
cvelistv5nvd
CVE-2019-10205MEDIUMCVSS 6.3vn/a2020-01-02
CVE-2019-10205 [MEDIUM] CWE-522 CVE-2019-10205: A flaw was found in the way Red Hat Quay stores robot account tokens in plain text. An attacker able
A flaw was found in the way Red Hat Quay stores robot account tokens in plain text. An attacker able to perform database queries in the Red Hat Quay database could use the tokens to read or write container images stored in the registry.
cvelistv5nvd