Back

MEDIUM

quay: insufficient session expiration

Published Mar 18, 2021

Description

A vulnerability was found in the Quay web application. Sessions in the Quay web application never expire. An attacker, able to gain access to a session, could use it to control or delete a user's container repository. Red Hat Quay 2 and 3 are vulnerable to this issue.

Affected products

Remediation

Red Hat mitigation

Toggle 'FEATURE_PERMANENT_SESSIONS' to 'False' in quay.conf.

Weaknesses (1)

References (4)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Mar 18, 2021
Updated Aug 4, 2024
Reserved Jan 3, 2019
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Low
Public date Mar 17, 2021