CVE Vulnerabilities

CVE-2019-10205

Insufficiently Protected Credentials

Published: Jan 02, 2020 | Modified: Feb 12, 2023
CVSS 3.x
6.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:H/A:H
CVSS 2.x
4.6 MEDIUM
AV:L/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
6 MODERATE
CVSS:3.0/AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:H/A:H
Ubuntu

A flaw was found in the way Red Hat Quay stores robot account tokens in plain text. An attacker able to perform database queries in the Red Hat Quay database could use the tokens to read or write container images stored in the registry.

Weakness

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

Affected Software

Name Vendor Start Version End Version
Quay Redhat 3.0.0 (including) 3.0.0 (including)
Red Hat Quay 3 RedHat quay3/clair-jwt:v3.2.0-6 *

Potential Mitigations

References