Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-3867

Опубликовано: 17 мар. 2021
Источник: redhat
CVSS3: 3.8
EPSS Низкий

Описание

A vulnerability was found in the Quay web application. Sessions in the Quay web application never expire. An attacker, able to gain access to a session, could use it to control or delete a user's container repository. Red Hat Quay 2 and 3 are vulnerable to this issue.

A vulnerability was found in the Quay web application. Sessions in the Quay web application never expire. An attacker, able to gain access to a session, could use it to control or delete a user's container repository.

Меры по смягчению последствий

Toggle 'FEATURE_PERMANENT_SESSIONS' to 'False' in quay.conf.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Quay 2quayWill not fix
Red Hat Quay 3quayWill not fix

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-613
https://bugzilla.redhat.com/show_bug.cgi?id=1772704quay: insufficient session expiration

EPSS

Процентиль: 29%
0.00108
Низкий

3.8 Low

CVSS3

Связанные уязвимости

CVSS3: 4.1
nvd
почти 5 лет назад

A vulnerability was found in the Quay web application. Sessions in the Quay web application never expire. An attacker, able to gain access to a session, could use it to control or delete a user's container repository. Red Hat Quay 2 and 3 are vulnerable to this issue.

github
больше 3 лет назад

A vulnerability was found in the Quay web application. Sessions in the Quay web application never expire. An attacker, able to gain access to a session, could use it to control or delete a user's container repository. Red Hat Quay 2 and 3 are vulnerable to this issue.

EPSS

Процентиль: 29%
0.00108
Низкий

3.8 Low

CVSS3