CVE-2024-3624

Severity CVSS v4.0:
Pending analysis
Type:
CWE-256 Plaintext Storage of a Password
Publication date:
25/04/2024
Last modified:
26/04/2024

Description

A flaw was found in how Quay's database is stored in plain-text in mirror-registry on the jinja's config.yaml file. This flaw allows a malicious actor with access to this file to gain access to Quay's database.