Skip to main content

Vendor/product archive

redhat / quay CVEs

Beta · best-effort

30 CVEs tagged to redhat / quay2 Critical, 11 High, 17 Medium, 0 Low, 0 Unrated.

CVE-2026-6848

Published Apr 22, 2026

A flaw was found in Red Hat Quay. When Red Hat Quay requests password re-verification for sensitive operations, such as token generation or robot account creation, the re-authenti…

CVSS 5.4 · Medium
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2025-4374

Published May 6, 2025

A flaw was found in Quay. When an organization acts as a proxy cache, and a user or robot pulls an image that hasn't been mirrored yet, they are granted "Admin" permissions on the…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-9683

Published Oct 17, 2024

A vulnerability was found in Quay, which allows successful authentication even when a truncated password version is provided. This flaw affects the authentication mechanism, reduc…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-5891

Published Jun 12, 2024

A vulnerability was found in Quay. If an attacker can obtain the client ID for an application, they can use an OAuth token to authenticate despite not having access to the organiz…

CVSS 4.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-4956

Published Nov 7, 2023

A flaw was found in Quay. Clickjacking is when an attacker uses multiple transparent or opaque layers to trick a user into clicking on a button or link on another page when they i…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-4959

Published Sep 15, 2023

A flaw was found in Quay. Cross-site request forgery (CSRF) attacks force a user to perform unwanted actions in an application. During the pentest, it was detected that the config…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-3384

Published Jul 24, 2023

A flaw was found in the Quay registry. While the image labels created through Quay undergo validation both in the UI and backend by applying a regex (validation.py), the same vali…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-3762

Published Mar 3, 2022

A directory traversal vulnerability was found in the ClairCore engine of Clair. An attacker can exploit this by supplying a crafted container image which, when scanned by Clair, a…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-27832

Published May 27, 2021

A flaw was found in Red Hat Quay, where it has a persistent Cross-site Scripting (XSS) vulnerability when displaying a repository's notification. This flaw allows an attacker to t…

CVSS 9.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-27831

Published May 27, 2021

A flaw was found in Red Hat Quay, where it does not properly protect the authorization token when authorizing email addresses for repository email notifications. This flaw allows…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-3867

Published Mar 18, 2021

A vulnerability was found in the Quay web application. Sessions in the Quay web application never expire. An attacker, able to gain access to a session, could use it to control or…

CVSS 4.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-14313

Published Aug 11, 2020

An information disclosure vulnerability was found in Red Hat Quay in versions before 3.3.1. This flaw allows an attacker who can create a build trigger in a repository, to disclos…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-3865

Published Jun 22, 2020

A vulnerability was found in quay-2, where a stored XSS vulnerability has been found in the super user function of quay. Attackers are able to use the name field of service key to…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-3864

Published Jan 21, 2020

A vulnerability was discovered in all quay-2 versions before quay-3.0.0, in the Quay web GUI where POST requests include a specific parameter which is used as a CSRF token. The to…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-10205

Published Jan 2, 2020

A flaw was found in the way Red Hat Quay stores robot account tokens in plain text. An attacker able to perform database queries in the Red Hat Quay database could use the tokens…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-25 of 30 CVEsPage 1 of 2