A flaw was found in the way Red Hat Quay stores robot account tokens in plain text. An attacker able to perform database queries in the Red Hat Quay database could use the tokens to read or write container images stored in the registry.
References
Link | Resource |
---|---|
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10205 | Issue Tracking Vendor Advisory |
Configurations
Information
Published : 2020-01-02 09:15
Updated : 2023-02-12 15:33
NVD link : CVE-2019-10205
Mitre link : CVE-2019-10205
JSON object : View
CWE
CWE-522
Insufficiently Protected Credentials
Products Affected
redhat
- quay