GHSA-fjvc-v8v8-pmj9MediumCVSS 5.4
A flaw was found in Quay. A cross-site scripting (XSS) vulnerability in the OAuth callback...
🔗 CVE IDs covered (1)
📋 Description
A flaw was found in Quay. A cross-site scripting (XSS) vulnerability in the OAuth callback handler allows a remote attacker to execute arbitrary JavaScript code within a user's browser session. By tricking a logged-in user into visiting a specially crafted link, an attacker can exploit improper input sanitization to run client-side scripts in the application context. Successful exploitation could allow the attacker to compromise the user's session, access sensitive registry information, or perform unauthorized actions on their behalf.