CVE-2023-3384

CVSS 3.1 Score 5.4 of 10 (medium)

Details

Published Jul 24, 2023
Updated: Nov 7, 2023
CWE ID 79

Summary

CVE-2023-3384 reveals a vulnerability in Quay registry where image labels created through the UI and backend undergo validation. However, the same validation does not apply to labels coming from images. This issue enables attackers to publish malicious images with embedded scripts, leading to Cross-site scripting (XSS) attacks when the images are executed.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share