A flaw was found in how Quay's database is stored in plain-text in mirror-registry on the jinja's config.yaml file. This flaw allows a malicious actor with access to this file to gain access to Quay's database.
Advisories
Source ID Title
EUVD EUVD EUVD-2024-32203 A flaw was found in how Quay's database is stored in plain-text in mirror-registry on the jinja's config.yaml file. This flaw allows a malicious actor with access to this file to gain access to Quay's database.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Tue, 24 Sep 2024 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2025-08-30T10:28:12.426Z

Reserved: 2024-04-10T18:03:04.115Z

Link: CVE-2024-3624

cve-icon Vulnrichment

Updated: 2024-08-01T20:20:00.402Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-04-25T18:15:10.170

Modified: 2024-11-21T09:30:00.973

Link: CVE-2024-3624

cve-icon Redhat

Severity : Moderate

Publid Date: 2024-04-10T00:00:00Z

Links: CVE-2024-3624 - Bugzilla

cve-icon OpenCVE Enrichment

No data.