6.5
CVSSv3

CVE-2023-4959

Published: 15/09/2023 Updated: 07/11/2023
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

A flaw was found in Quay. Cross-site request forgery (CSRF) attacks force a user to perform unwanted actions in an application. During the pentest, it was detected that the config-editor page is vulnerable to CSRF. The config-editor page is used to configure the Quay instance. By coercing the victim’s browser into sending an attacker-controlled request from another domain, it is possible to reconfigure the Quay instance (including adding users with admin privileges).

Vulnerable Product Search on Vulmon Subscribe to Product

redhat quay 3.0.0

Vendor Advisories

Description<!---->A flaw was found in Quay Cross-site request forgery (CSRF) attacks force a user to perform unwanted actions in an application During the pentest, it was detected that the config-editor page is vulnerable to CSRF The config-editor page is used to configure the Quay instance By coercing the victim&amp;rsquo;s browser into sendin ...