CVE-2024-3625: Mirror-registry: redis password stored in plain-text
A flaw was found in Quay, where Quay's database is stored in plain text in mirror-registry on Jinja's config.yaml file. This issue leaves the possibility of a malicious actor with access to this file to gain access to Quay's Redis instance.
Other sources
The Quay's database is stored in plain-text in mirror-registry on the jinja's config.yaml file, leaving the possibility of an malicious actor with permissions to access this file to gain access to Quay's Redis instance.
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-3625?
CVE-2024-3625 has a high severity due to the exposure of sensitive database information in plain text.
How do I fix CVE-2024-3625?
To fix CVE-2024-3625, secure the Jinja's config.yaml file by encrypting the database credentials and restricting access to authorized users.
What software is affected by CVE-2024-3625?
The affected software for CVE-2024-3625 is Red Hat Quay.
What are the potential risks of CVE-2024-3625?
The risks of CVE-2024-3625 include unauthorized access to Quay's Redis instance and potential data breaches.
How can I verify if my system is vulnerable to CVE-2024-3625?
You can verify if your system is vulnerable to CVE-2024-3625 by checking if the database credentials are stored in plain text within the Jinja's config.yaml file.