Token Storage Vulnerability in Red Hat Quay
CVE-2019-10205
6MEDIUM
Summary
A vulnerability exists in Red Hat Quay related to the storage of robot account tokens in plain text within the database. This flaw could enable an attacker with the capability to execute database queries to exploit the tokens, potentially granting them the ability to read or write container images stored within the registry. This raises significant security concerns regarding unauthorized access to sensitive container images.
Affected Version(s)
quay
References
CVSS V3.1
Score:
6
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
High
Availability:
Low
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved