CVE-2019-10205

A flaw was found in the way Red Hat Quay stores robot account tokens in plain text. An attacker able to perform database queries in the Red Hat Quay database could use the tokens to read or write container images stored in the registry.
References
Link Resource
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10205 Issue Tracking Vendor Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:redhat:quay:3.0.0:*:*:*:*:*:*:*

History

12 Feb 2023, 23:33

Type Values Removed Values Added
References
  • {'url': 'https://access.redhat.com/errata/RHSA-2019:4341', 'name': 'https://access.redhat.com/errata/RHSA-2019:4341', 'tags': [], 'refsource': 'MISC'}
  • {'url': 'https://access.redhat.com/security/cve/CVE-2019-10205', 'name': 'https://access.redhat.com/security/cve/CVE-2019-10205', 'tags': [], 'refsource': 'MISC'}
  • {'url': 'https://bugzilla.redhat.com/show_bug.cgi?id=1732190', 'name': 'https://bugzilla.redhat.com/show_bug.cgi?id=1732190', 'tags': [], 'refsource': 'MISC'}

02 Feb 2023, 21:18

Type Values Removed Values Added
References
  • (MISC) https://access.redhat.com/errata/RHSA-2019:4341 -
  • (MISC) https://access.redhat.com/security/cve/CVE-2019-10205 -
  • (MISC) https://bugzilla.redhat.com/show_bug.cgi?id=1732190 -

Information

Published : 2020-01-02 17:15

Updated : 2023-12-10 13:13


NVD link : CVE-2019-10205

Mitre link : CVE-2019-10205

CVE.ORG link : CVE-2019-10205


JSON object : View

Products Affected

redhat

  • quay
CWE
CWE-522

Insufficiently Protected Credentials