4.4
CVSSv2

CVE-2019-3867

Published: 18/03/2021 Updated: 25/03/2021
CVSS v2 Base Score: 4.4 | Impact Score: 6.4 | Exploitability Score: 3.4
CVSS v3 Base Score: 4.1 | Impact Score: 3.4 | Exploitability Score: 0.7
VMScore: 392
Vector: AV:L/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

A vulnerability was found in the Quay web application. Sessions in the Quay web application never expire. An attacker, able to gain access to a session, could use it to control or delete a user's container repository. Red Hat Quay 2 and 3 are vulnerable to this issue.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

redhat quay 2.0.0

redhat quay 3.0.0

Vendor Advisories

A vulnerability was found in the Quay web application Sessions in the Quay web application never expire An attacker, able to gain access to a session, could use it to control or delete a user's container repository ...