First published: Mon Jun 22 2020(Updated: )
A vulnerability was found in quay-2, where a stored XSS vulnerability has been found in the super user function of quay. Attackers are able to use the name field of service key to inject scripts and make it run when admin users try to change the name.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Redhat Quay | =2.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-3865 is a vulnerability found in quay-2 that allows for stored cross-site scripting (XSS) attacks.
The vulnerability affects Redhat Quay version 2.0.0.
CVE-2019-3865 has a severity rating of medium, with a CVSS score of 6.1.
Attackers can exploit the vulnerability by injecting scripts into the name field of a service key, which will execute when admin users try to change the name.
To fix CVE-2019-3865, update your Redhat Quay installation to a version that includes the patched vulnerability.