Vulnerabilities
Vulnerable Software
Redhat:  >> Quay  >> 1.13.2  Security Vulnerabilities
An information disclosure vulnerability was found in Red Hat Quay in versions before 3.3.1. This flaw allows an attacker who can create a build trigger in a repository, to disclose the names of robot accounts and the existence of private repositories within any namespace.
CVSS Score
4.3
EPSS Score
0.002
Published
2020-08-11
A vulnerability was discovered in all quay-2 versions before quay-3.0.0, in the Quay web GUI where POST requests include a specific parameter which is used as a CSRF token. The token is not refreshed for every request or when a user logged out and in again. An attacker could use a leaked token to gain access to the system using the user's account.
CVSS Score
5.4
EPSS Score
0.002
Published
2020-01-21


Contact Us

Shodan ® - All rights reserved