cbcvebase.

Redhat Quay vulnerabilities

31 known vulnerabilities affecting redhat/quay.

Total CVEs
31
CISA KEV
1
actively exploited
Public exploits
1
Exploited in wild
1
Severity breakdown
CRITICAL2HIGH12MEDIUM17

Vulnerabilities

Page 2 of 2
CVE-2024-9683P4MEDIUMCVSS 5.3v3.0.02024-10-17
CVE-2024-9683 [MEDIUM] CWE-305 CVE-2024-9683: A vulnerability was found in Quay, which allows successful authentication even when a truncated pass A vulnerability was found in Quay, which allows successful authentication even when a truncated password version is provided. This flaw affects the authentication mechanism, reducing the overall security of password enforcement. While the risk is relatively low due to the typical length of the passwords used (73 characters), this vulnerability can sti
nvd
CVE-2023-4959P4MEDIUMCVSS 6.5v3.0.02023-09-15
CVE-2023-4959 [MEDIUM] CWE-352 CVE-2023-4959: A flaw was found in Quay. Cross-site request forgery (CSRF) attacks force a user to perform unwanted A flaw was found in Quay. Cross-site request forgery (CSRF) attacks force a user to perform unwanted actions in an application. During the pentest, it was detected that the config-editor page is vulnerable to CSRF. The config-editor page is used to configure the Quay instance. By coercing the victim’s browser into sending an attacker-controlled reques
nvd
CVE-2026-2376P4MEDIUMCVSS 5.4v3.0.02026-03-12
CVE-2026-2376 [MEDIUM] CWE-601 CVE-2026-2376: A flaw was found in mirror-registry where an authenticated user can trick the system into accessing A flaw was found in mirror-registry where an authenticated user can trick the system into accessing unintended internal or restricted systems by providing malicious web addresses. When the application processes these addresses, it automatically follows redirects without verifying the final destination, allowing attackers to route requests to systems t
nvd
CVE-2023-3384P4MEDIUMCVSS 5.4v3.0.02023-07-24
CVE-2023-3384 [MEDIUM] CWE-79 CVE-2023-3384: A flaw was found in the Quay registry. While the image labels created through Quay undergo validatio A flaw was found in the Quay registry. While the image labels created through Quay undergo validation both in the UI and backend by applying a regex (validation.py), the same validation is not performed when the label comes from an image. This flaw allows an attacker to publish a malicious image to a public registry containing a script that can be exec
nvd
CVE-2019-10205P4MEDIUMCVSS 6.3v3.0.02020-01-02
CVE-2019-10205 [MEDIUM] CWE-522 CVE-2019-10205: A flaw was found in the way Red Hat Quay stores robot account tokens in plain text. An attacker able A flaw was found in the way Red Hat Quay stores robot account tokens in plain text. An attacker able to perform database queries in the Red Hat Quay database could use the tokens to read or write container images stored in the registry.
nvd
CVE-2019-3865P4MEDIUMCVSS 6.1v2.0.02020-06-22
CVE-2019-3865 [MEDIUM] CWE-79 CVE-2019-3865: A vulnerability was found in quay-2, where a stored XSS vulnerability has been found in the super us A vulnerability was found in quay-2, where a stored XSS vulnerability has been found in the super user function of quay. Attackers are able to use the name field of service key to inject scripts and make it run when admin users try to change the name.
nvd
CVE-2020-27831P4MEDIUMCVSS 4.3≥ 3.0.0, < 3.3.3vQuay 3.3.32021-05-27
CVE-2020-27831 [MEDIUM] CWE-284 CVE-2020-27831: A flaw was found in Red Hat Quay, where it does not properly protect the authorization token when au A flaw was found in Red Hat Quay, where it does not properly protect the authorization token when authorizing email addresses for repository email notifications. This flaw allows an attacker to add email addresses they do not own to repository notifications.
nvd
CVE-2024-5891P4MEDIUMCVSS 4.2v3.0.02024-06-12
CVE-2024-5891 [MEDIUM] CWE-1390 CVE-2024-5891: A vulnerability was found in Quay. If an attacker can obtain the client ID for an application, they A vulnerability was found in Quay. If an attacker can obtain the client ID for an application, they can use an OAuth token to authenticate despite not having access to the organization from which the application was created. This issue is limited to authentication and not authorization. However, in configurations where endpoints rely only on authentic
nvd
CVE-2023-4956P4MEDIUMCVSS 4.3v3.0.02023-11-07
CVE-2023-4956 [MEDIUM] CWE-1021 CVE-2023-4956: A flaw was found in Quay. Clickjacking is when an attacker uses multiple transparent or opaque layer A flaw was found in Quay. Clickjacking is when an attacker uses multiple transparent or opaque layers to trick a user into clicking on a button or link on another page when they intend to click on the top-level page. During the pentest, it has been detected that the config-editor page is vulnerable to clickjacking. This flaw allows an attacker to tri
nvd
CVE-2020-14313P4MEDIUMCVSS 4.3fixed in 3.3.1vQuay versions before 3.3.12020-08-11
CVE-2020-14313 [MEDIUM] CVE-2020-14313: An information disclosure vulnerability was found in Red Hat Quay in versions before 3.3.1. This fla An information disclosure vulnerability was found in Red Hat Quay in versions before 3.3.1. This flaw allows an attacker who can create a build trigger in a repository, to disclose the names of robot accounts and the existence of private repositories within any namespace.
nvd
CVE-2019-3867P4MEDIUMCVSS 4.1v2.0.0v3.0.0+1 more2021-03-18
CVE-2019-3867 [MEDIUM] CWE-613 CVE-2019-3867: A vulnerability was found in the Quay web application. Sessions in the Quay web application never ex A vulnerability was found in the Quay web application. Sessions in the Quay web application never expire. An attacker, able to gain access to a session, could use it to control or delete a user's container repository. Red Hat Quay 2 and 3 are vulnerable to this issue.
nvd
Redhat Quay vulnerabilities | cvebase