📦 Quay

by Redhat

🔍 What is Quay?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2021-3762

CRITICAL CVSS 9.8 Mar 3, 2022

A directory traversal vulnerability in ClairCore allows attackers to write arbitrary files to the filesystem by uploading a malicious container image. This can lead to remote code execution. Organizat...

CVE-2020-27832

CRITICAL CVSS 9.0 May 27, 2021

CVE-2020-27832 is a persistent cross-site scripting (XSS) vulnerability in Red Hat Quay that allows attackers to inject malicious scripts into repository notifications. When exploited, this can trick ...

CVE-2023-44487

HIGH CVSS 7.5 Oct 10, 2023

CVE-2023-44487 is an HTTP/2 protocol vulnerability that allows attackers to cause denial of service by rapidly resetting streams, consuming server resources. This affects any system using HTTP/2, incl...

CVE-2022-1227

HIGH CVSS 8.8 Apr 29, 2022

CVE-2022-1227 is a privilege escalation vulnerability in Podman that allows attackers to gain host filesystem access when users run 'podman top' on malicious container images. This affects Podman user...

CVE-2025-4374

MEDIUM CVSS 6.5 May 6, 2025

A privilege escalation vulnerability in Quay container registry allows users or robots to gain administrative permissions on newly created repositories when pulling unmirrored images through an organi...

CVE-2024-5891

MEDIUM CVSS 4.2 Jun 12, 2024

This vulnerability in Quay allows attackers who obtain an application's client ID to use OAuth tokens for authentication, potentially accessing applications they shouldn't have access to. It affects s...