SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2019-10205

An attacker able to perform database queries in the Red Hat Quay database could use the tokens to read or write container images stored in the registry.

MEDIUM 6.3EPSS 0.27%

Does this matter?

Lower severity and a low EPSS score (0.27%). Track it; it rarely justifies an emergency change on its own.

Description

A flaw was found in the way Red Hat Quay stores robot account tokens in plain text. An attacker able to perform database queries in the Red Hat Quay database could use the tokens to read or write container images stored in the registry.

CVSS 3.1
6.3 MEDIUMCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:H/A:H
EPSS
0.27% probability · 19th percentile
CISA KEV
Not listed
Weakness
CWE-522
Affected
redhat/quay
Source
secalert@redhat.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.