MEDIUM
quay: insufficient session expiration
Published Mar 18, 2021
4.1
MEDIUMCVSS 3.1
EPSS 0.29%
Description
A vulnerability was found in the Quay web application. Sessions in the Quay web application never expire. An attacker, able to gain access to a session, could use it to control or delete a user's container repository. Red Hat Quay 2 and 3 are vulnerable to this issue.
Affected products
- Vendor n/a Product Quay Defaultn/a
- Version As shipped in Red Hat Quay 2 and 3.StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| n/a | Quay | n/a |
|
No data.
Red Hat Quay 2
quay
Will not fix
Red Hat Quay 3
quay
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Quay 2 | quay | Will not fix | n/a |
| Red Hat Quay 3 | quay | Will not fix | n/a |
No package ranges for this CVE.
Remediation
Red Hat mitigation
Toggle 'FEATURE_PERMANENT_SESSIONS' to 'False' in quay.conf.
Weaknesses (1)
References (4)
- https://access.redhat.com/security/cve/CVE-2019-3867 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1772704 x_refsource_MISCIssue TrackingMitigationThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2019-3867
- https://www.cve.org/CVERecord?id=CVE-2019-3867
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2019-3867 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1772704 | x_refsource_MISCIssue TrackingMitigationThird Party Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2019-3867 | ||
| https://www.cve.org/CVERecord?id=CVE-2019-3867 |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Mar 18, 2021
Updated Aug 4, 2024
Reserved Jan 3, 2019
Link CVE-2019-3867
CISA Vulnrichment
Updated n/a