4.6
CVSSv2

CVE-2019-10205

Published: 02/01/2020 Updated: 12/02/2023
CVSS v2 Base Score: 4.6 | Impact Score: 6.4 | Exploitability Score: 3.9
CVSS v3 Base Score: 6.3 | Impact Score: 5.5 | Exploitability Score: 0.8
VMScore: 409
Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

A flaw was found in the way Red Hat Quay stores robot account tokens in plain text. An attacker able to perform database queries in the Red Hat Quay database could use the tokens to read or write container images stored in the registry.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

redhat quay 3.0.0

Vendor Advisories

Synopsis Moderate: Red Hat Quay v320 security and bug fix update Type/Severity Security Advisory: Moderate Topic An update is now available for Red Hat Quay 3Red Hat Product Security has rated this update as having a security impact of Moderate A Common Vulnerability Scoring System (CVSS) base score, wh ...
Impact: Moderate Public Date: 2019-09-18 CWE: CWE-522 Bugzilla: 1732190: CVE-2019-10205 quay: Red Hat Q ...