CVE-2019-3864: CSRF
Published Jan 21, 2020
·Updated
A vulnerability was discovered in all quay-2 versions before quay-3.0.0, in the Quay web GUI where POST requests include a specific parameter which is used as a CSRF token. The token is not refreshed for every request or when a user logged out and in again. An attacker could use a leaked token to gain access to the system using the user's account.
Affected Software
1 affected component
redhat Quay<3.0.0
Event History
Jan 21, 2020
CVE Published
via MITRE·03:44 PM
Data Sourced
via MITRE·03:44 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2019-3864?
CVE-2019-3864 is a vulnerability in all quay-2 versions before quay-3.0.0 in the Quay web GUI.
2
What is the severity of CVE-2019-3864?
The severity of CVE-2019-3864 is high with a severity value of 8.8.
3
How does CVE-2019-3864 affect software?
CVE-2019-3864 affects Redhat Quay versions before 3.0.0.
4
What is the CWE of CVE-2019-3864?
The CWE of CVE-2019-3864 is 352.
5
Is there a reference for CVE-2019-3864?
Yes, you can find more information about CVE-2019-3864 at https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3864.