CVE-2024-3624
Severity CVSS v4.0:
Pending analysis
Type:
CWE-256
Plaintext Storage of a Password
Publication date:
25/04/2024
Last modified:
26/04/2024
Description
A flaw was found in how Quay's database is stored in plain-text in mirror-registry on the jinja's config.yaml file. This flaw allows a malicious actor with access to this file to gain access to Quay's database.
Impact
Base Score 3.x
7.30
Severity 3.x
HIGH



