Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2019-3867


A vulnerability was found in the Quay web application. Sessions in the Quay web application never expire. An attacker, able to gain access to a session, could use it to control or delete a user's container repository. Red Hat Quay 2 and 3 are vulnerable to this issue.


Published

2021-03-18T19:15:13.137

Last Modified

2024-11-21T04:42:45.320

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 4.1 (MEDIUM)

CVSSv2 Vector

AV:L/AC:M/Au:N/C:P/I:P/A:P

  • Access Vector: LOCAL
  • Access Complexity: MEDIUM
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: PARTIAL
  • Availability Impact: PARTIAL
Exploitability Score

3.4

Impact Score

6.4

Weaknesses
  • Type: Primary
    CWE-613

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application redhat quay 2.0.0 Yes
Application redhat quay 3.0.0 Yes

References