Bugzilla – Bug 1222717
VUL-0: CVE-2024-3623: mirror-registry: Default database secret key stored in plain-text on initial configuration file
Last modified: 2024-04-12 09:10:51 UTC
The default DATABASE_SECRET_KEY field is stored in plain text on the jinja's config.yaml file, leaving the possibility of every mirror-registry installation which hasn't changed ot to have the same DATABASE_SECRET_KEY. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2024-3623 https://bugzilla.redhat.com/show_bug.cgi?id=2274404
This is for quay/mirror-registry not thkukuk/mirror-registry. Closing