PT-2020-2293 · Red Hat · Red Hat Quay
Sean Smith
·
Published
2020-01-02
·
Updated
2023-02-12
·
CVE-2019-10205
CVSS v2.0
6.4
Medium
| Vector | AV:L/AC:L/Au:S/C:P/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Red Hat Quay (affected versions not specified)
Description
A flaw in Red Hat Quay allows robot account tokens to be stored in plain text. This could enable an attacker, who can perform database queries in the Red Hat Quay database, to use these tokens and access container images stored in the registry, potentially allowing them to read or write these images. The issue is related to insufficient protection of registration data, which could allow an attacker to bypass container protection.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Insufficiently Protected Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Red Hat Quay