CVE-2019-3864

A vulnerability was discovered in all quay-2 versions before quay-3.0.0, in the Quay web GUI where POST requests include a specific parameter which is used as a CSRF token. The token is not refreshed for every request or when a user logged out and in again. An attacker could use a leaked token to gain access to the system using the user's account.
References
Link Resource
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3864 Issue Tracking Vendor Advisory
Configurations

Configuration 1

cpe:2.3:a:redhat:quay:*:*:*:*:*:*:*:*

Information

Published : 2020-01-21 04:15

Updated : 2020-02-05 05:52


NVD link : CVE-2019-3864

Mitre link : CVE-2019-3864

Products Affected
No products.
CWE