Impact
A flaw in Red Hat Quay allows a remote attacker to trick a user into logging in through a crafted link, leading to execution of arbitrary script in the context of the victim's authenticated browser session. The application does not validate the redirect destination before navigating, so an attacker can inject malicious code that runs with the user's privileges and can be used to steal credentials, hijack sessions, or perform other malicious actions within the Quay application.
Affected Systems
Red Hat Quay 3 deployments that use direct database authentication are affected. No specific sub‑versions are listed.
Risk and Exploitability
The CVSS score of 4.2 indicates low to moderate severity. EPSS data is not available and the vulnerability is not listed in the CISA KEV catalog. Successful exploitation requires the target to use direct database authentication and the victim to follow a malicious login URL, implying a user‑interaction attack but with no additional infrastructure prerequisites.
OpenCVE Enrichment