Security Advisory

CVE-2024-3625

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2024-04-25 17:46:52
Last updated 2025-11-20 18:38:39
Assigner redhat
CVSS score not scored
State PUBLISHED

Description

A flaw was found in Quay, where Quay's database is stored in plain text in mirror-registry on Jinja's config.yaml file. This issue leaves the possibility of a malicious actor with access to this file to gain access to Quay's Redis instance.