Filtered by vendor Redhat
Subscriptions
Filtered by product Mirror Registry
Subscriptions
Total
4 CVE
CVE | Vendors | Products | Updated | CVSS v3.1 |
---|---|---|---|---|
CVE-2024-3625 | 1 Redhat | 1 Mirror Registry | 2024-09-24 | 7.3 High |
A flaw was found in Quay, where Quay's database is stored in plain text in mirror-registry on Jinja's config.yaml file. This issue leaves the possibility of a malicious actor with access to this file to gain access to Quay's Redis instance. | ||||
CVE-2024-3624 | 1 Redhat | 1 Mirror Registry | 2024-09-24 | 7.3 High |
A flaw was found in how Quay's database is stored in plain-text in mirror-registry on the jinja's config.yaml file. This flaw allows a malicious actor with access to this file to gain access to Quay's database. | ||||
CVE-2024-3623 | 1 Redhat | 1 Mirror Registry | 2024-09-24 | 8.1 High |
A flaw was found when using mirror-registry to install Quay. It uses a default database secret key, which is stored in plain-text format in one of the configuration template files. This issue may lead to all instances of Quay deployed using mirror-registry to have the same database secret key. This flaw allows a malicious actor to access sensitive information from Quay's database. | ||||
CVE-2024-3622 | 1 Redhat | 1 Mirror Registry | 2024-09-24 | 8.8 High |
A flaw was found when using mirror-registry to install Quay. It uses a default secret, which is stored in plain-text format in one of the configuration template files. This issue may lead to all instances of Quay deployed using mirror-registry to have the same secret key. This flaw allows a malicious actor to craft session cookies and as a consequence, it may lead to gaining access to the affected Quay instance. |
Page 1 of 1.