A flaw was found in the way Red Hat Quay stores robot account tokens in plain text. An attacker able to perform database queries in the Red Hat Quay database could use the tokens to read or write container images stored in the registry.
References
Link | Resource |
---|---|
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10205 | Issue Tracking Vendor Advisory |
Configurations
History
No history.
Information
Published : 2020-01-02 17:15
Updated : 2024-02-04 20:39
NVD link : CVE-2019-10205
Mitre link : CVE-2019-10205
CVE.ORG link : CVE-2019-10205
JSON object : View
Products Affected
redhat
- quay
CWE
CWE-522
Insufficiently Protected Credentials