CVE-2023-3384
CVSS 3.1 Score 5.4 of 10 (medium)
Details
Published Jul 24, 2023
Updated: Nov 7, 2023
CWE ID 79
Summary
CVE-2023-3384 reveals a vulnerability in Quay registry where image labels created through the UI and backend undergo validation. However, the same validation does not apply to labels coming from images. This issue enables attackers to publish malicious images with embedded scripts, leading to Cross-site scripting (XSS) attacks when the images are executed.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share