A flaw was found in Quay, where Quay's database is stored...
High severity
Unreviewed
Published
Apr 25, 2024
to the GitHub Advisory Database
•
Updated Apr 25, 2024
Description
Published by the National Vulnerability Database
Apr 25, 2024
Published to the GitHub Advisory Database
Apr 25, 2024
Last updated
Apr 25, 2024
A flaw was found in Quay, where Quay's database is stored in plain text in mirror-registry on Jinja's config.yaml file. This issue leaves the possibility of a malicious actor with access to this file to gain access to Quay's Redis instance.
References