cvedb.io
CVE-2023-3384
MEDIUM · CVSS 5.4
EPSS exploitation probability: 0%
Published 2023-07-24T16:15:12.523 · Last modified 2026-08-06T11:16:27.590

Summary

A flaw was found in the Quay registry. While the image labels created through Quay undergo validation both in the UI and backend by applying a regex (validation.py), the same validation is not performed when the label comes from an image. This flaw allows an attacker to publish a malicious image to a public registry containing a script that can be executed via Cross-site scripting (XSS).

Affected products

redhat — quay

Does this affect you?

Add your gear to cvedb and we'll alert you only when redhat ships something exploited.

Check my exposure →

References

This product uses data from the NVD API but is not endorsed or certified by the NVD. Informational only; not professional security advice.