Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-3384

Опубликовано: 24 июл. 2023
Источник: nvd
CVSS3: 5.4
EPSS Низкий

Описание

A flaw was found in the Quay registry. While the image labels created through Quay undergo validation both in the UI and backend by applying a regex (validation.py), the same validation is not performed when the label comes from an image. This flaw allows an attacker to publish a malicious image to a public registry containing a script that can be executed via Cross-site scripting (XSS).

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:redhat:quay:3.0.0:*:*:*:*:*:*:*

EPSS

Процентиль: 56%
0.00338
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-79
CWE-79

Связанные уязвимости

CVSS3: 5.4
redhat
больше 2 лет назад

A flaw was found in the Quay registry. While the image labels created through Quay undergo validation both in the UI and backend by applying a regex (validation.py), the same validation is not performed when the label comes from an image. This flaw allows an attacker to publish a malicious image to a public registry containing a script that can be executed via Cross-site scripting (XSS).

CVSS3: 5.4
github
больше 2 лет назад

A flaw was found in the Quay registry. While the image labels created through Quay undergo validation both in the UI and backend by applying a regex (validation.py), the same validation is not performed when the label comes from an image. This flaw allows an attacker to publish a malicious image to a public registry containing a script that can be executed via Cross-site scripting (XSS).

EPSS

Процентиль: 56%
0.00338
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-79
CWE-79