CVE-2024-3623

A flaw was found when using mirror-registry to install Quay. It uses a default database secret key, which is stored in plain-text format in one of the configuration template files. This issue may lead to all instances of Quay deployed using mirror-registry to have the same database secret key. This flaw allows a malicious actor to access sensitive information from Quay's database.
Configurations

Configuration 1 (hide)

cpe:2.3:a:redhat:mirror_registry:-:*:*:*:*:*:*:*

History

30 Jul 2025, 14:34

Type Values Removed Values Added
First Time Redhat
Redhat mirror Registry
CPE cpe:2.3:a:redhat:mirror_registry:-:*:*:*:*:*:*:*
References () https://access.redhat.com/security/cve/CVE-2024-3623 - () https://access.redhat.com/security/cve/CVE-2024-3623 - Vendor Advisory
References () https://bugzilla.redhat.com/show_bug.cgi?id=2274404 - () https://bugzilla.redhat.com/show_bug.cgi?id=2274404 - Issue Tracking, Vendor Advisory

21 Nov 2024, 09:30

Type Values Removed Values Added
References () https://access.redhat.com/security/cve/CVE-2024-3623 - () https://access.redhat.com/security/cve/CVE-2024-3623 -
References () https://bugzilla.redhat.com/show_bug.cgi?id=2274404 - () https://bugzilla.redhat.com/show_bug.cgi?id=2274404 -
Summary
  • (es) Se encontró una falla al usar el registro espejo para instalar Quay. Utiliza una clave secreta de base de datos predeterminada, que se almacena en formato de texto plano en uno de los archivos de plantilla de configuración. Este problema puede provocar que todas las instancias de Quay implementadas mediante el registro espejo tengan la misma clave secreta de la base de datos. Esta falla permite que un actor malintencionado acceda a información confidencial de la base de datos de Quay.

25 Apr 2024, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-04-25 18:15

Updated : 2025-07-30 14:34


NVD link : CVE-2024-3623

Mitre link : CVE-2024-3623

CVE.ORG link : CVE-2024-3623


JSON object : View

Products Affected

redhat

  • mirror_registry
CWE
CWE-256

Plaintext Storage of a Password