CVE-2019-3864 - CVE House
Back to Database
Status published Medium CVE-2019-3864

A vulnerability was discovered in all quay-2 versions before quay-3.0.0,...

Vulnerability Description

A vulnerability was discovered in all quay-2 versions before quay-3.0.0, in the Quay web GUI where POST requests include a specific parameter which is used as a CSRF token. The token is not refreshed for every request or when a user logged out and in again. An attacker could use a leaked token to gain access to the system using the user's account.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2019-3864

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

quay
Vulnerable Versions:
all quay-2 versions before quay-3.0.0

Timeline

Official Publish: January 21st, 2020
Last Modified: August 4th, 2024
Added to House: July 20th, 2026

CVSS Vectors

V3: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N

Weaknesses (CWE)