Red Hat Quay是美国红帽(Red Hat)公司的一款分布式容器镜像仓库,它主要用于构建、分布和部署容器。 Red Hat Quay存在安全漏洞,该漏洞源于存在跨站脚本(XSS)漏洞,允许攻击者将恶意映像发布到公共注册表。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Red Hat | Red Hat Quay 3 | v3.9.9-1< * |
unaffected |
v3.9.9-3< * |
unaffected | ||
v3.9.9-1< * |
unaffected | ||
v3.9.9-2< * |
unaffected | ||
v3.9.9-3< * |
unaffected | ||
v3.9.9-1< * |
unaffected | ||
v3.9.9-1< * |
unaffected | ||
v3.9.9-8< * |
unaffected | ||
| … +2 more rows | |||
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Red Hat | Red Hat Quay 3 | v3.9.9-1 ~ * |
cpe:/a:redhat:quay:3::el8
|
|
| Red Hat | Red Hat Quay 3 | v3.9.9-3 ~ * |
cpe:/a:redhat:quay:3::el8
|
|
| Red Hat | Red Hat Quay 3 | v3.9.9-1 ~ * |
cpe:/a:redhat:quay:3::el8
|
|
| Red Hat | Red Hat Quay 3 | v3.9.9-2 ~ * |
cpe:/a:redhat:quay:3::el8
|
|
| Red Hat | Red Hat Quay 3 | v3.9.9-3 ~ * |
cpe:/a:redhat:quay:3::el8
|
|
| Red Hat | Red Hat Quay 3 | v3.9.9-1 ~ * |
cpe:/a:redhat:quay:3::el8
|
|
| Red Hat | Red Hat Quay 3 | v3.9.9-1 ~ * |
cpe:/a:redhat:quay:3::el8
|
|
| Red Hat | Red Hat Quay 3 | v3.9.9-8 ~ * |
cpe:/a:redhat:quay:3::el8
|
|
| Red Hat | Red Hat Quay 3 | v3.9.9-1 ~ * |
cpe:/a:redhat:quay:3::el8
|
|
| Red Hat | Red Hat Quay 3 | v3.9.9-5 ~ * |
cpe:/a:redhat:quay:3::el8
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2023-3812 | 7.8 HIGH | Kernel: tun: bugs for oversize packet when napi frags enabled in tun_napi_alloc_frags |
| CVE-2023-38200 | 7.5 HIGH | Keylime: registrar is subject to a dos against ssl connections |
| CVE-2023-3567 | 7.1 HIGH | Kernel: use after free in vcs_read in drivers/tty/vt/vc_screen.c due to race |
| CVE-2023-3640 | 7.0 HIGH | Kernel: x86/mm: a per-cpu entry area leak was identified through the init_cea_offsets func |
| CVE-2023-33952 | 6.7 MEDIUM | Kernel: vmwgfx: double free within the handling of vmw_buffer_object objects |
| CVE-2023-33951 | 6.7 MEDIUM | Kernel: vmwgfx: race condition leading to information disclosure vulnerability |
| CVE-2023-3750 | 6.5 MEDIUM | Libvirt: improper locking in virstoragepoolobjlistsearch may lead to denial of service |
| CVE-2023-3019 | 6.0 MEDIUM | Qemu: e1000e: heap use-after-free in e1000e_write_packet_to_guest() |
| CVE-2023-3745 | 5.5 MEDIUM | Imagemagick: heap-buffer-overflow in pushcharpixel() in quantum-private.h |
No comments yet