Impact
A flaw was discovered in Red Hat Quay 3 that allows a remote attacker to execute arbitrary JavaScript in a user’s browser through the OAuth callback handler when the callback URL includes a format=json parameter. The vulnerability arises from insufficient input sanitization of the callback format, which triggers a DOM‑based cross‑site scripting (XSS) flaw identified as CWE‑79. By persuading a logged‑in user to visit a specially crafted link, the attacker can run client‑side scripts in the application context, potentially hijacking the session, accessing registry data, or performing unauthorized actions on the user’s behalf.
Affected Systems
The affected product is Red Hat Quay, version 3. No specific sub‑versions are listed; the CVE references a generic Quay 3 installation.
Risk and Exploitability
The CVSS score of 5.4 indicates a medium severity XSS flaw, but the EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog. The attacker can remotely exploit the flaw by directing a victim to a maliciously formatted OAuth callback URL; no local privileges or physical access are required. Although the exploitation requires a logged‑in user to click the link, the impact on session integrity and confidentiality is significant enough to warrant timely remediation when a patch becomes available.
OpenCVE Enrichment