Vulnerabilities
Vulnerable Software
Redhat:  >> Quay  >> 3.0.2  Security Vulnerabilities
A flaw was found in Red Hat Quay, where it has a persistent Cross-site Scripting (XSS) vulnerability when displaying a repository's notification. This flaw allows an attacker to trick a user into performing a malicious action to impersonate the target user. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.
CVSS Score
9.0
EPSS Score
0.004
Published
2021-05-27
A flaw was found in Red Hat Quay, where it does not properly protect the authorization token when authorizing email addresses for repository email notifications. This flaw allows an attacker to add email addresses they do not own to repository notifications.
CVSS Score
4.3
EPSS Score
0.001
Published
2021-05-27
An information disclosure vulnerability was found in Red Hat Quay in versions before 3.3.1. This flaw allows an attacker who can create a build trigger in a repository, to disclose the names of robot accounts and the existence of private repositories within any namespace.
CVSS Score
4.3
EPSS Score
0.002
Published
2020-08-11


Contact Us

Shodan ® - All rights reserved