CVE-2019-3865: XSS
A vulnerability was found in quay-2, where a stored XSS vulnerability has been found in the super user function of quay. Attackers are able to use the name field of service key to inject scripts and make it run when admin users try to change the name.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-3865?
CVE-2019-3865 is a vulnerability found in quay-2 that allows for stored cross-site scripting (XSS) attacks.
What software versions are affected by CVE-2019-3865?
The vulnerability affects Redhat Quay version 2.0.0.
What is the severity of CVE-2019-3865?
CVE-2019-3865 has a severity rating of medium, with a CVSS score of 6.1.
How does CVE-2019-3865 work?
Attackers can exploit the vulnerability by injecting scripts into the name field of a service key, which will execute when admin users try to change the name.
How can I fix CVE-2019-3865?
To fix CVE-2019-3865, update your Redhat Quay installation to a version that includes the patched vulnerability.