Redhat

Mirror Registry

3 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.04%
  • Veröffentlicht 20.08.2025 11:38:59
  • Zuletzt bearbeitet 20.08.2025 16:15:43

The mirror-registry doesn't properly sanitize the host header HTTP header in HTTP request received, allowing an attacker to perform malicious redirects to attacker-controlled domains or phishing campaigns.

  • EPSS 0.12%
  • Veröffentlicht 25.04.2024 18:15:09
  • Zuletzt bearbeitet 30.07.2025 14:41:38

A flaw was found when using mirror-registry to install Quay. It uses a default secret, which is stored in plain-text format in one of the configuration template files. This issue may lead to all instances of Quay deployed using mirror-registry to hav...

  • EPSS 0.09%
  • Veröffentlicht 25.04.2024 18:15:09
  • Zuletzt bearbeitet 30.07.2025 14:34:41

A flaw was found when using mirror-registry to install Quay. It uses a default database secret key, which is stored in plain-text format in one of the configuration template files. This issue may lead to all instances of Quay deployed using mirror-re...