See how project quay compares to other vendors in security performance
A DOM-based cross-site scripting flaw was found in Project Quay's signin page (Signin.tsx). After a user completes a successful direct database login, the component reads the redirecturl query parameter and assigns it to window.location.href without validating the URL scheme or origin. An attacker can set redirecturl to a javascript: URI, causing arbitrary JavaScript execution in the authenticated Quay session after login. Exploitation requires the target deployment to use database authentication and the user to successfully authenticate through the crafted URL.
A DOM-based cross-site scripting (XSS) flaw was found in Project Quay's OAuth local callback handler (OAuthLocalHandler.tsx). When the format=json query parameter is supplied, the component reads the accesstoken from the URL fragment and assigns it to document.body.innerHTML via JSON.stringify, which does not HTML-encode angle brackets. An attacker can craft a URL containing a malicious accesstoken in the fragment that, when clicked by a Quay user, executes arbitrary JavaScript in the Quay registry origin. The format=json code path bypasses OAuth state validation and requires no authentication.