CVE-2019-3864

A vulnerability was discovered in all quay-2 versions before quay-3.0.0, in the Quay web GUI where POST requests include a specific parameter which is used as a CSRF token. The token is not refreshed for every request or when a user logged out and in again. An attacker could use a leaked token to gain access to the system using the user's account.
References
Link Resource
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3864 Issue Tracking Vendor Advisory
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

cpe:2.3:a:redhat:quay:*:*:*:*:*:*:*:*

Information

Published : 2020-01-21 08:15

Updated : 2020-02-05 09:52


NVD link : CVE-2019-3864

Mitre link : CVE-2019-3864


JSON object : View

CWE
CWE-352

Cross-Site Request Forgery (CSRF)

Advertisement

dedicated server usa

Products Affected

redhat

  • quay