CVE-2019-10205

A flaw was found in the way Red Hat Quay stores robot account tokens in plain text. An attacker able to perform database queries in the Red Hat Quay database could use the tokens to read or write container images stored in the registry.
References
Link Resource
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10205 Issue Tracking Vendor Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10205 Issue Tracking Vendor Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:redhat:quay:3.0.0:*:*:*:*:*:*:*

History

21 Nov 2024, 04:18

Type Values Removed Values Added
References () https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10205 - Issue Tracking, Vendor Advisory () https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10205 - Issue Tracking, Vendor Advisory

Information

Published : 2020-01-02 17:15

Updated : 2024-11-21 04:18


NVD link : CVE-2019-10205

Mitre link : CVE-2019-10205

CVE.ORG link : CVE-2019-10205


JSON object : View

Products Affected

redhat

  • quay
CWE
CWE-522

Insufficiently Protected Credentials