Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-pf92-7x8p-6x5m

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

A vulnerability was found in the Quay web application. Sessions in the Quay web application never expire. An attacker, able to gain access to a session, could use it to control or delete a user's container repository. Red Hat Quay 2 and 3 are vulnerable to this issue.

A vulnerability was found in the Quay web application. Sessions in the Quay web application never expire. An attacker, able to gain access to a session, could use it to control or delete a user's container repository. Red Hat Quay 2 and 3 are vulnerable to this issue.

EPSS

Процентиль: 29%
0.00108
Низкий

Дефекты

CWE-613

Связанные уязвимости

CVSS3: 3.8
redhat
почти 5 лет назад

A vulnerability was found in the Quay web application. Sessions in the Quay web application never expire. An attacker, able to gain access to a session, could use it to control or delete a user's container repository. Red Hat Quay 2 and 3 are vulnerable to this issue.

CVSS3: 4.1
nvd
почти 5 лет назад

A vulnerability was found in the Quay web application. Sessions in the Quay web application never expire. An attacker, able to gain access to a session, could use it to control or delete a user's container repository. Red Hat Quay 2 and 3 are vulnerable to this issue.

EPSS

Процентиль: 29%
0.00108
Низкий

Дефекты

CWE-613