← Back

CVE-2019-10205

nvd nist
Published: Jan 2, 2020Modified: Nov 21, 2024

JSON object

Loading...
6.3
Vector
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:H/A:H
Exploitability: 0.8 / Impact: 5.5
Source: NVD

Description

A flaw was found in the way Red Hat Quay stores robot account tokens in plain text. An attacker able to perform database queries in the Red Hat Quay database could use the tokens to read or write container images stored in the registry.

Affected (1)

Products: Redhat: Quay
1 product
Quay
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 3.0.0

References (2)

Source: secalert@redhat.com
Issue TrackingVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingVendor Advisory

Timeline

No history available yet.